VulnerAlert



APPLICATION
BROWSER
DATABASE
17-12-2025 23:54

CVE-2025-68147 Vulnerabilidad documentada

Sin puntuación
Tags
#xss
#site
#cross
#data
#web
#using
#source
#php
#open
#javascript
#java
#form
#cross-site
#config
#admin
#database
#browser
#application
#vulnerability
#/view(.*)admin(.*)as/iU
#view admin as
#/data(.*)java/iU
#data java
#cross-site scripting
#scripting
#patched
#patch
#malicious
#inject
#hijack
#execute
#compromise
#configuration
#csrf
#attack
#access
#unauthorized
Descripción
Open Source Point of Sale (opensourcepos) is a web based point sale application written in PHP using CodeIgniter framework. Starting version 3.4.0 and prior to 3.4.2, Stored Cross-Site Scripting (XSS) vulnerability exists the "Return Policy" configuration field. The does not properly sanitize user input before saving it database or displaying on receipts. An attacker with access "Store Configuration" (such as rogue administrator an account compromised via separate CSRF vulnerability) can inject malicious JavaScript payloads into this These are executed browser any (including other administrators sales staff) whenever they view receipt complete transaction. This lead session hijacking, theft sensitive data, unauthorized actions performed behalf victim. has been patched 3.4.2 by ensuring output escaped `esc()` function template. As temporary mitigation, should ensure field contains only plain text strictly avoid entering HTML tags. There no code-based workaround than applying patch.
https://github.com/Nixon-H/CVE-2025-68147-OSPOS-Stored-XSS
https://github.com/opensourcepos/opensourcepos/commit/22297a
https://github.com/opensourcepos/opensourcepos/security/advisories/GHSA-xgr7-7pvw-fpmh
Referencia
CVE-2025-68147
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-68147
Resultados similares
Coincidentes en almenos en 50% de los tags
18-12-2025 CVE-2025-64231
Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Con...
Ver información
17-12-2025 CVE-2023-53917
Affiliate Me version 5.0.1 contains a SQL injection vulnerability in the admin.php endpoint tha...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por