PT-2026-3640 · Abacre · Abacre Retail Point Of Sale

CVE-2025-67263

·

Published

2026-01-20

·

Updated

2026-01-20

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Abacre Retail Point of Sale version 14.0.0.396
Description The application does not properly sanitize user-supplied input in the Name and Surname fields within the Clients module, leading to a stored cross-site scripting (XSS) issue. An attacker can inject malicious HTML or script content into these fields, which is then saved in the database.
Recommendations Ensure proper sanitization of user input for the Name and Surname fields in the Clients module.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67263

Affected Products

Abacre Retail Point Of Sale