Vulnerabilities
Vulnerable Software
Wallaceit:  >> Wallacepos  >> 1.4.3  Security Vulnerabilities
Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks via a crafted sales transaction.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-07-31
Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-07-31
Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.
CVSS Score
7.2
EPSS Score
0.025
Published
2019-07-31


Contact Us

Shodan ® - All rights reserved