CVE-2025-41011

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phppointofsale:php_point_of_sale:19.4:*:*:*:*:*:*:*

History

06 May 2026, 20:34

Type Values Removed Values Added
CPE cpe:2.3:a:phppointofsale:php_point_of_sale:19.4:*:*:*:*:*:*:*
First Time Phppointofsale php Point Of Sale
Phppointofsale
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://www.incibe.es/en/incibe-cert/notices/aviso/html-injection-php-point-sale-0 - () https://www.incibe.es/en/incibe-cert/notices/aviso/html-injection-php-point-sale-0 - Third Party Advisory

21 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 16:16

Updated : 2026-05-06 20:34


NVD link : CVE-2025-41011

Mitre link : CVE-2025-41011

CVE.ORG link : CVE-2025-41011


JSON object : View

Products Affected

phppointofsale

  • php_point_of_sale
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')