Lucene search

K
cvelistTMLCVELIST:CVE-2022-40294
HistoryOct 31, 2022 - 8:09 p.m.

CVE-2022-40294 CSV Injection in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC

2022-10-3120:09:23
CWE-1236
TML
www.cve.org
php point of sale
llc
data export
malicious code embedded

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "PHP Point of Sale",
    "vendor": "PHP Point of Sale LLC",
    "versions": [
      {
        "status": "affected",
        "version": "19.0"
      }
    ]
  }
]

9.1 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.9%

Related for CVELIST:CVE-2022-40294