Vulnerability Description
Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensourcepos | Open Source Point Of Sale | 3.3.7 |
Related Weaknesses (CWE)
References
- https://grimthereaperteam.medium.com/open-source-point-of-sale-v3-3-7-file-uploaExploitThird Party Advisory
- https://grimthereaperteam.medium.com/open-source-point-of-sale-v3-3-7-file-uploaExploitThird Party Advisory
FAQ
What is CVE-2022-34578?
CVE-2022-34578 is a vulnerability with a CVSS score of 7.2 (HIGH). Open Source Point of Sale v3.3.7 was discovered to contain an arbitrary file upload vulnerability via the Update Branding Settings page.
How severe is CVE-2022-34578?
CVE-2022-34578 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-34578?
Check the references section above for vendor advisories and patch information. Affected products include: Opensourcepos Open Source Point Of Sale.