PT-2026-41666 · Unknown · Open Source Point Of Sale

Kamran Saifullah

·

Published

2026-05-18

·

Updated

2026-05-18

·

CVE-2026-8802

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions opensourcepos Open Source Point of Sale versions prior to 3.4.3
Description A path traversal issue exists in the getPicThumb() function within the app/Controllers/Items.php file. This occurs due to the improper manipulation of the pic filename argument, which allows a remote attacker to access files and directories outside the intended folder.
Recommendations Apply patch def0c27a0e252668df8d942fc31e16d1edfd7323 to remediate the issue. As a temporary workaround, restrict access to the getPicThumb() function until the patch is applied.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-8802

Affected Products

Open Source Point Of Sale