Описание
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protection mechanism was explicitly disabled, allowing the application to process state-changing requests (POST) without verifying a valid CSRF token. An unauthenticated remote attacker can exploit this by hosting a malicious web page. If a logged-in administrator visits this page, their browser is forced to send unauthorized requests to the application. A successful exploit allows the attacker to silently create a new Administrator account with full privileges, leading to a complete takeover of the system and loss of confidentiality, integrity, and availability. The vulnerability has been patched in version 3.4.2. The fix re-enables the CSRF filter in app/Config/Filters.php and resolves associa
Ссылки
- ExploitThird Party Advisory
- Patch
- Issue Tracking
- ExploitVendor Advisory
- ExploitThird Party Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
EPSS
8.8 High
CVSS3
Дефекты
EPSS
8.8 High
CVSS3