Lucene search

K
cvelistTMLCVELIST:CVE-2022-40288
HistoryOct 31, 2022 - 8:05 p.m.

CVE-2022-40288 Stored cross-site scripting in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC via messaging functionality

2022-10-3120:05:35
CWE-79
TML
www.cve.org
2
cve-2022-40288
stored cross-site scripting
php point of sale

AI Score

8

Confidence

High

EPSS

0.001

Percentile

42.8%

The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "PHP Point of Sale",
    "vendor": "PHP Point of Sale LLC",
    "versions": [
      {
        "status": "affected",
        "version": "0"
      }
    ]
  }
]

AI Score

8

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVELIST:CVE-2022-40288