PT-2022-22217 · Unknown · Open Source Point Of Sale

Published

2022-07-28

·

Updated

2022-08-04

·

CVE-2022-34578

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Source Point of Sale version 3.3.7
Description The issue is related to an arbitrary file upload vulnerability. This vulnerability can be exploited via the Update Branding Settings page.
Recommendations For Open Source Point of Sale version 3.3.7, consider restricting access to the Update Branding Settings page until a patch is available. As a temporary workaround, avoid using the branding settings update feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-34578

Affected Products

Open Source Point Of Sale