CVE-2025-41011 MEDIUM

CVE-2025-41011: HTML injection in PHP Point Of Sale

Vendor Php Point Of Sale
Product PHP Point Of Sale
Weakness CWE-79 · XSS
Published April 21, 2026
Last update April 21, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N

What the vulnerability does

Description

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.

Key dates

Disclosure timeline

April 21, 2026 CVE published
April 21, 2026 Record updated