PT-2026-41666 · Unknown · Open Source Point Of Sale

·

CVE-2026-8802

·

Published

2026-05-18

·

Updated

2026-05-18

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions opensourcepos Open Source Point of Sale versions prior to 3.4.3
Description A path traversal issue exists in the getPicThumb() function within the app/Controllers/Items.php file. This occurs due to the improper manipulation of the pic filename argument, which allows a remote attacker to access files and directories outside the intended folder.
Recommendations Apply patch def0c27a0e252668df8d942fc31e16d1edfd7323 to remediate the issue. As a temporary workaround, restrict access to the getPicThumb() function until the patch is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8802
GHSA-XQ63-3V4G-39R5

Affected Products

Open Source Point Of Sale