PHP Point of Sale是PHP Point of Sale公司的一个小型零售企业的在线销售点系统。 PHP Point of Sale 19.0版本存在跨站脚本漏洞,该漏洞源于其消息传递功能允许经过身份验证攻击者通过存储型跨站点脚本导致权限升级或目标帐户受到损害。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHP Point of Sale LLC | PHP Point of Sale | 0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-40288 | Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC v | |
| CVE-2022-40289 | Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC v | |
| CVE-2022-40290 | Reflected cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LL | |
| CVE-2022-40291 | Cross-site request forgery (CSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, | |
| CVE-2022-40292 | Unauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sa | |
| CVE-2022-40293 | Session fixation in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. | |
| CVE-2022-40294 | CSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC | |
| CVE-2022-40295 | Authenticated sensitive information disclosure in PHP Point of Sale version 19.0, by PHP P | |
| CVE-2022-40296 | Server-side request forgery (SSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale |
No comments yet