Aller au contenu

Fiche vulnérabilité

CVE-2025-41011 : faille moyenne phppointofsale php point of sale (CVSS 6.1)

Description

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.

En bref

Sévérité
Moyenne (CVSS 6.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
21 avr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • phppointofsale php point of sale

Références

Rechercher une autre vulnérabilité dans la base CVE