vendor:
Point of Sale System
by:
Saeed Bala Ahmed (r0b0tG4nG)
7.5
CVSS
HIGH
Multiple Stored XSS
79
CWE
Product Name: Point of Sale System
Affected Version From: Version 1
Affected Version To: Not provided
Patch Exists: NO
Related CWE: Not provided
CPE: a:point_of_sale_system:1.0
Platforms Tested: Parrot OS
2020
Point of Sale System 1.0 – Multiple Stored XSS
This exploit allows an attacker to execute arbitrary script code in the Point of Sale System 1.0 application. The vulnerability can be triggered by injecting a malicious script in various fields of the application, including the Suppliers, Customers, and Products pages. When the injected script is executed, it can lead to unauthorized access, data theft, or other malicious activities.
Mitigation:
To mitigate this vulnerability, the vendor should implement input validation and sanitization mechanisms to prevent the execution of arbitrary scripts. Users are advised to update to a patched version of the application, if available.