Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-39380

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Apr 07, 2026
Vendor unknown

Description

Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Locations configuration feature. The application fails to properly sanitize user input supplied through the stock_location parameter, allowing attackers to inject malicious JavaScript code that is stored in the database and executed when rendered in the Employees interface. This vulnerability is fixed in 3.4.3.

References