Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-60503

Опубликовано: 03 нояб. 2025
Источник: nvd
CVSS3: 8.7
EPSS Низкий

Описание

A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session, which could lead to session hijacking or other malicious actions.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ultimatefosters:ultimatepos:4.8:*:*:*:*:*:*:*

EPSS

Процентиль: 13%
0.00044
Низкий

8.7 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.7
github
3 месяца назад

A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute arbitrary JavaScript in the context of an administrator's browser session, which could lead to session hijacking or other malicious actions.

EPSS

Процентиль: 13%
0.00044
Низкий

8.7 High

CVSS3

Дефекты

CWE-79