Описание
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.
Ссылки
- ExploitThird Party Advisory
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00152
Низкий
7.2 High
CVSS3
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 7.2
github
около 2 месяцев назад
A Cross-site scripting (XSS) vulnerability in Create/Update Customer(s) in Open Source Point of Sale v3.4.1 allows remote attackers to inject arbitrary web script or HTML via the phone_number parameter.
EPSS
Процентиль: 36%
0.00152
Низкий
7.2 High
CVSS3
Дефекты
CWE-20