Stored Cross-Site Scripting Vulnerability in Open Source Point of Sale Application
CVE-2026-32712

5.4MEDIUM

Key Information:

Vendor
CVE Published:
7 April 2026

What is CVE-2026-32712?

The Open Source Point of Sale application has a security vulnerability in the Daily Sales management table, where the customer_name column is improperly configured to escape HTML. This flaw allows attackers with customer management permissions to inject malicious JavaScript into the first_name or last_name fields. As a result, any user viewing the Daily Sales page may inadvertently execute this script in their browser, potentially compromising user data and security. The vulnerability is resolved in version 3.4.3.

Affected Version(s)

opensourcepos < 3.4.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.