PT-2026-3640 · Abacre · Abacre Retail Point Of Sale
CVE-2025-67263
·
Publicado
2026-01-20
·
Atualizado
2026-01-20
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Abacre Retail Point of Sale version 14.0.0.396
Description
The application does not properly sanitize user-supplied input in the Name and Surname fields within the Clients module, leading to a stored cross-site scripting (XSS) issue. An attacker can inject malicious HTML or script content into these fields, which is then saved in the database.
Recommendations
Ensure proper sanitization of user input for the Name and Surname fields in the Clients module.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Abacre Retail Point Of Sale