PT-2025-44782 · Ultimatefosters · Ultimatepos

Published

2025-11-03

·

Updated

2026-02-03

·

CVE-2025-60503

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ultimatefosters UltimatePOS version 4.8
Description A cross-site scripting (XSS) flaw exists in the administrative interface of the software. Input provided in the purchase functionality is reflected without proper sanitization in the admin log panel page, specifically within the 'reference No.' field. This allows an authenticated attacker to inject and execute arbitrary JavaScript code within an administrator's browser session, potentially leading to session hijacking or other malicious activities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60503

Affected Products

Ultimatepos