PT-2026-41666 · Unknown · Open Source Point Of Sale
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X |
Name of the Vulnerable Software and Affected Versions
opensourcepos Open Source Point of Sale versions prior to 3.4.3
Description
A path traversal issue exists in the
getPicThumb() function within the app/Controllers/Items.php file. This occurs due to the improper manipulation of the pic filename argument, which allows a remote attacker to access files and directories outside the intended folder.Recommendations
Apply patch def0c27a0e252668df8d942fc31e16d1edfd7323 to remediate the issue.
As a temporary workaround, restrict access to the
getPicThumb() function until the patch is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Source Point Of Sale