Cross-Site Request Forgery Vulnerability in Open Source Point of Sale by Open Source POS
CVE-2025-68434
What is CVE-2025-68434?
A serious Cross-Site Request Forgery (CSRF) vulnerability exists in Open Source Point of Sale, affecting versions 3.4.0 to 3.4.1. The CSRF protection was explicitly disabled, allowing attackers to perform state-changing actions via unauthorized requests. If a logged-in administrator accesses a malicious webpage, it can result in unauthorized creation of a new administrator account with full system privileges. This exploits the lack of CSRF token verification, putting the application at high risk for potential takeover and subsequent exposure of sensitive data. The issue has been addressed in version 3.4.2, which re-enables CSRF protection and resolves prior AJAX race conditions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
opensourcepos >= 3.4.0, < 3.4.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
