PT-2026-73035 · Unknown · Open Source Point Of Sale

·

CVE-2026-19895

·

Published

2026-08-15

·

Updated

2026-09-02

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions opensourcepos Open Source Point of Sale versions prior to 3.4.3
Description An issue exists in the Login Endpoint component within the Login::index function of the app/Config/Filters.php file. This flaw allows for the improper restriction of excessive authentication attempts, which could be exploited remotely. The attack is characterized by high complexity and difficult exploitability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19895

Affected Products

Open Source Point Of Sale