PT-2025-36404 · Itsourcecode+1 · Itsourcecode Pos Point Of Sale System+1

Alphabug

·

Published

2025-09-07

·

Updated

2025-09-09

·

CVE-2025-10065

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions itsourcecode POS Point of Sale System version 1.0
Description A weakness exists in itsourcecode POS Point of Sale System that allows for cross site scripting. The issue is related to the manipulation of the scripts argument and impacts an unknown function within the file /inventory/main/vendors/datatables/unit testing/templates/dom data th.php. The attack can be carried out remotely. The exploit has been made publicly available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-10065

Affected Products

Datatables
Itsourcecode Pos Point Of Sale System