LionCoders SalePro POS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Customer Management Module of LionCoders SalePro POS version 5.4.8. This vulnerability allows authenticated attackers to inject arbitrary web scripts or HTML into the 'Customer Name' parameter while creating or editing customer profiles. The injected malicious content is not properly sanitized before being stored and later displayed, which can result in the execution of scripts in the browsers of users who view the affected customer details.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the customer details.

Reproduction

To reproduce this vulnerability, an authenticated user can create or edit a customer profile in LionCoders SalePro POS 5.4.8. During this process, the user can inject a script or HTML payload into the 'Customer Name' parameter. Once the profile is saved, the injected content will be executed in the browser when the customer details are viewed.

Added: Oct 6, 2025, 6:19 PM
Updated: Oct 6, 2025, 8:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.