Path Traversal Vulnerability in Open Source Point of Sale by OpenSourcePOS
CVE-2026-8802
5.3MEDIUM
What is CVE-2026-8802?
A vulnerability has been identified in the Open Source Point of Sale (OpenSourcePOS) software, impacting versions 3.4.1 and 3.4.2. This flaw resides in the getPicThumb function within the app/Controllers/Items.php file, where improper validation of the pic_filename argument can lead to path traversal attacks. Attackers may exploit this remotely, potentially accessing unauthorized files on the system. To mitigate this issue, users are advised to apply the provided patch identified by commit def0c27a0e252668df8d942fc31e16d1edfd7323 promptly.
Affected Version(s)
Open Source Point of Sale 3.4.0
Open Source Point of Sale 3.4.1
Open Source Point of Sale 3.4.2
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kamran Saifullah (VulDB User)
VulDB CNA Team
