PT-2025-44782 · Ultimatefosters · Ultimatepos

CVE-2025-60503

·

Published

2025-11-03

·

Updated

2026-02-03

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ultimatefosters UltimatePOS version 4.8
Description A cross-site scripting (XSS) flaw exists in the administrative interface of the software. Input provided in the purchase functionality is reflected without proper sanitization in the admin log panel page, specifically within the 'reference No.' field. This allows an authenticated attacker to inject and execute arbitrary JavaScript code within an administrator's browser session, potentially leading to session hijacking or other malicious activities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60503

Affected Products

Ultimatepos