Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2025-63800
- EPSS 0.45%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 16:51:22
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` param...
7.2
CVE-2022-34578
- EPSS 1.13%
- Veröffentlicht 28.07.2022 20:15:11
- Zuletzt bearbeitet 21.11.2024 07:09:47
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.