Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqrw-hvqv-r58w

Опубликовано: 20 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This allows an attacker with access to modify the currency_symbol value to inject arbitrary SQL expressions, which are executed when the affected query is subsequently processed.

OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This allows an attacker with access to modify the currency_symbol value to inject arbitrary SQL expressions, which are executed when the affected query is subsequently processed.

EPSS

Процентиль: 20%
0.00065
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 5.3
nvd
4 месяца назад

OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This allows an attacker with access to modify the currency_symbol value to inject arbitrary SQL expressions, which are executed when the affected query is subsequently processed.

EPSS

Процентиль: 20%
0.00065
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-89