CVE Published: 31/10/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: TML |
Vendor: PHP Point of Sale LLC |
Product: PHP Point of Sale Status : PUBLISHED
CVE-2022-40289 Description
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the upload and download functionality, which could be leveraged to escalate privileges or compromise any accounts they can coerce into observing the targeted files.