PHP Point Of Sale
cpe:2.3:a:phppointofsale:php_point_of_sale:*:*:*:*:*:*:*
- 19.4
A HTML injection vulnerability exists in PHP Point of Sale version 19.4. This issue allows an attacker to inject and render HTML in the browser of a victim. The vulnerability arises from inadequate validation of user input. Exploitation involves sending a request to '/reports/generate/specific_customer' with the 'start_date_formatted' and 'end_date_formatted' parameters.
Exploitation of this vulnerability allows for HTML injection, which could be used to execute scripts in the context of the user's browser.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.