Vulnerability Description
HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phppointofsale | Php Point Of Sale | 19.4 |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/html-injection-php-point-saleThird Party Advisory
FAQ
What is CVE-2025-41011?
CVE-2025-41011 is a vulnerability with a CVSS score of 6.1 (MEDIUM). HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a requ...
How severe is CVE-2025-41011?
CVE-2025-41011 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-41011?
Check the references section above for vendor advisories and patch information. Affected products include: Phppointofsale Php Point Of Sale.