Open Source Point of Sale version 2.3.1 suffers from a persistent cross site scripting vulnerability.
f1671bce7a9da376f8b83740a41aa9d21414efb032bfcb02310d72edd617c40b
Vulnerability title: Stored XSS In Open Source Point of Sale
CVE: CVE-2015-0299
Vendor: http://sourceforge.net/projects/opensourcepos/
Product: Open Source Point of Sale
Affected version: 2.3.1
Fixed version: -
Reported by: Arturo Rodriguez
Details:
Multiple parameters are vulnerable to stored XSS within the application. The attacker needs to be authenticated in order to exploit this vulnerability.