Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-68434

Опубликовано: 17 дек. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Starting in version 3.4.0 and prior to version 3.4.2, a Cross-Site Request Forgery (CSRF) vulnerability exists in the application's filter configuration. The CSRF protection mechanism was explicitly disabled, allowing the application to process state-changing requests (POST) without verifying a valid CSRF token. An unauthenticated remote attacker can exploit this by hosting a malicious web page. If a logged-in administrator visits this page, their browser is forced to send unauthorized requests to the application. A successful exploit allows the attacker to silently create a new Administrator account with full privileges, leading to a complete takeover of the system and loss of confidentiality, integrity, and availability. The vulnerability has been patched in version 3.4.2. The fix re-enables the CSRF filter in app/Config/Filters.php and resolves associa

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:opensourcepos:open_source_point_of_sale:*:*:*:*:*:*:*:*
Версия от 3.4.0 (включая) до 3.4.2 (исключая)

EPSS

Процентиль: 30%
0.00111
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

EPSS

Процентиль: 30%
0.00111
Низкий

8.8 High

CVSS3

Дефекты

CWE-352