Back

CRITICAL

Server-side request forgery (SSRF) in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.

Published Oct 31, 2022

Description

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TML
Published Oct 31, 2022
Updated May 6, 2025
Reserved Sep 8, 2022
CISA Vulnrichment
Updated May 6, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner TML
Published Oct 31, 2022
Updated May 6, 2025
Exploited since n/a
EUVD-2022-43593