Stored Cross-Site Scripting Vulnerability in Open Source Point of Sale Application
CVE-2026-32712
5.4MEDIUM
What is CVE-2026-32712?
The Open Source Point of Sale application has a security vulnerability in the Daily Sales management table, where the customer_name column is improperly configured to escape HTML. This flaw allows attackers with customer management permissions to inject malicious JavaScript into the first_name or last_name fields. As a result, any user viewing the Daily Sales page may inadvertently execute this script in their browser, potentially compromising user data and security. The vulnerability is resolved in version 3.4.3.
Affected Version(s)
opensourcepos < 3.4.3
