Cleartext Transmission Vulnerability in LionCoders SalePro POS Software
CVE-2025-10776
Key Information:
- Vendor
Lioncoders
- Status
- Vendor
- CVE Published:
- 22 September 2025
Badges
What is CVE-2025-10776?
A vulnerability has been identified in LionCoders SalePro POS, affecting versions up to 5.5.0. This flaw occurs in the Login component, where sensitive information may be transmitted in cleartext. This allows for potential interception by malicious actors, making it easier for attackers to access confidential data remotely. The complexity of exploiting this vulnerability is considered high, and although it is publicly known, the vendor has not responded to early disclosures regarding the issue. Organizations using the affected versions should take immediate action to safeguard against this risk.
Affected Version(s)
SalePro POS 5.0
SalePro POS 5.1
SalePro POS 5.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved