Vulnerability Details CVE-2022-40294
The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be embedded within export data and then triggered in exported data viewers.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 29.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-40294
-
cpe:2.3:a:phppointofsale:php_point_of_sale:19.0