CVE-2025-70092 Details
Description
A cross-site scripting (XSS) vulnerability in the Item Kits function of OpenSourcePOS v3.4.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Item Name parameter.
A stored cross-site scripting vulnerability has been identified in OpenSourcePOS version 3.4.1, specifically within the Item Kits function. This vulnerability allows authenticated users with item management privileges to inject arbitrary web scripts or HTML into the Item Name parameter. The injected payload is executed when the crafted item is selected while creating a new Item Kit.
Users are advised to apply strict output encoding, such as HTML entity encoding, before rendering item names in the Item Kits interface. Input validation should also be enforced for the Item Name field. Additionally, a review of other item-related fields and modules for similar XSS issues is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hungnqdz/cve-research/blob/main/CVE-2025-70092.md | [email protected] | ExploitMitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| opensourcepos open source point of sale | 3.4.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 18, 2026 | Initial Analysis | [email protected] |
| Feb 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | New CVE Received | [email protected] |