Description
HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.
Published: 2026-04-21
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: HTML injection allows attackers to render malicious HTML in a victim’s browser, potentially leading to cross‑site scripting attacks.
Action: Monitor
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

There is no solution reported at this time.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 06 May 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:phppointofsale:php_point_of_sale:19.4:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Wed, 22 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Phppointofsale
Phppointofsale php Point Of Sale
Vendors & Products Phppointofsale
Phppointofsale php Point Of Sale

Tue, 21 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.
Title HTML injection in PHP Point Of Sale
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Phppointofsale Php Point Of Sale
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-04-21T16:21:50.544Z

Reserved: 2025-04-16T09:08:43.217Z

Link: CVE-2025-41011

cve-icon Vulnrichment

Updated: 2026-04-21T16:21:45.456Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-21T16:16:19.143

Modified: 2026-05-06T20:34:36.533

Link: CVE-2025-41011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T11:46:21Z

Weaknesses