Path Traversal Vulnerability in Open Source Point of Sale by OpenSourcePOS
CVE-2026-8802

5.3MEDIUM

Key Information:

Vendor
CVE Published:
18 May 2026

What is CVE-2026-8802?

A vulnerability has been identified in the Open Source Point of Sale (OpenSourcePOS) software, impacting versions 3.4.1 and 3.4.2. This flaw resides in the getPicThumb function within the app/Controllers/Items.php file, where improper validation of the pic_filename argument can lead to path traversal attacks. Attackers may exploit this remotely, potentially accessing unauthorized files on the system. To mitigate this issue, users are advised to apply the provided patch identified by commit def0c27a0e252668df8d942fc31e16d1edfd7323 promptly.

Affected Version(s)

Open Source Point of Sale 3.4.0

Open Source Point of Sale 3.4.1

Open Source Point of Sale 3.4.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamran Saifullah (VulDB User)
VulDB CNA Team
.