PT-2025-45449 · Ycf1998 · Money-Pos System

Published

2025-11-07

·

Updated

2026-02-05

·

CVE-2025-63689

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ycf1998 money-pos system versions prior to commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14)
Description The ycf1998 money-pos system contains multiple SQL injection vulnerabilities. A remote attacker can potentially execute arbitrary code by manipulating the orderby parameter.
Recommendations Update ycf1998 money-pos system to commit 11f276bd20a41f089298d804e43cb1c39d041e59 (2025-09-14) or a later version.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-63689

Affected Products

Money-Pos System