PT-2026-31017 · Opensourcepos · Opensourcepos

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-32712

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Daily Sales management table. The customer name column is configured with escape: false in the bootstrap-table column configuration, causing customer names to be rendered as raw HTML. An attacker with customer management permissions can inject arbitrary JavaScript into a customer's first name or last name field, which executes in the browser of any user viewing the Daily Sales page. This vulnerability is fixed in 3.4.3.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-32712

Affected Products

Opensourcepos