PHP Point of Sale是PHP Point of Sale公司的一个小型零售企业的在线销售点系统。 PHP Point of Sale 19.0版本存在安全漏洞,该漏洞源于其允许攻击者通过跨站请求伪造实现胁迫用户向站点发送恶意请求以删除他们的帐户,或者在极少数情况下劫持他们的帐户并创建其他管理帐户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PHP Point of Sale LLC | PHP Point of Sale | 0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-40287 | Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC v | |
| CVE-2022-40288 | Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC v | |
| CVE-2022-40289 | Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC v | |
| CVE-2022-40290 | Reflected cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LL | |
| CVE-2022-40292 | Unauthenticated username enumeration in PHP Point of Sale version 19.0, by PHP Point of Sa | |
| CVE-2022-40293 | Session fixation in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC. | |
| CVE-2022-40294 | CSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC | |
| CVE-2022-40295 | Authenticated sensitive information disclosure in PHP Point of Sale version 19.0, by PHP P | |
| CVE-2022-40296 | Server-side request forgery (SSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale |
No comments yet