PT-2025-51847 · Unknown · Open Source Point Of Sale
Omkaryepre
·
Published
2025-12-17
·
Updated
2025-12-17
·
CVE-2025-66921
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Open Source Point of Sale version 3.4.1
Description
A Cross-site scripting (XSS) issue exists in the Create/Update Item(s) Module. This allows remote attackers to inject arbitrary web script or HTML via the
name parameter.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the
name parameter to prevent the injection of malicious scripts.Exploit
Fix
XSS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Open Source Point Of Sale