Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Auspicious-Rook

#42733of 53,608
6.1Total CVSS
Vulnerabilities · 1
PT-2025-40921
6.1
2025-10-06
Lioncoders · Salepro Pos · CVE-2025-56382
**Name of the Vulnerable Software and Affected Versions** LionCoders SalePro POS version 5.4.8 **Description** A stored Cross-site scripting (XSS) issue exists within the Customer Management Module. An authenticated attacker can inject arbitrary web script or HTML through the `Customer Name` parameter during customer profile creation or modification. Improper sanitization of this input before storage and rendering results in script execution in the browsers of users viewing the affected customer details. **Recommendations** Apply updates to address the improper sanitization of the `Customer Name` parameter in the Customer Management Module.