PHP Point of Sale是PHP Point of Sale公司的一个小型零售企业的在线销售点系统。 PHP Point of Sale 19.0版本存在安全漏洞,该漏洞源于其用户配置文件数据字段允许经过身份验证攻击者通过存储型跨站点脚本导致提升查看用户配置文件的任何帐户中的特权,并危及该帐户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHP Point of Sale LLC | PHP Point of Sale | 0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-40287 | Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC v | |
| CVE-2022-40289 | Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC v | |
| CVE-2022-40290 | Reflected cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LL | |
| CVE-2022-40291 | Cross-site request forgery (CSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, | |
| CVE-2022-40292 | Unauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sa | |
| CVE-2022-40293 | Session fixation in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. | |
| CVE-2022-40294 | CSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC | |
| CVE-2022-40295 | Authenticated sensitive information disclosure in PHP Point of Sale version 19.0, by PHP P | |
| CVE-2022-40296 | Server-side request forgery (SSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale |
No comments yet