opensourcepos Open Source Point of Sale Items.php getPicThumb path traversal
Published May 18, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.57%
Description
A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argument pic_filename results in path traversal. The attack may be launched remotely. The patch is identified as def0c27a0e252668df8d942fc31e16d1edfd7323. A patch should be applied to remediate this issue. The vendor was contacted early about this disclosure.
Affected products
-
- Version 3.4.0StatusaffectedConstraints-
- Version 3.4.1StatusaffectedConstraints-
- Version 3.4.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Opensourcepos | Open Source Point of Sale | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://github.com/opensourcepos/opensourcepos/commit/def0c27a0e252668df8d942fc31e16d1edfd7323 patch
- https://github.com/opensourcepos/opensourcepos/pull/4545 issue-trackingpatch
- https://github.com/opensourcepos/opensourcepos/security/advisories/GHSA-xq63-3v4g-39r5 broken-link
- https://vuldb.com/submit/802559 third-party-advisory
- https://vuldb.com/vuln/364435 vdb-entrytechnical-description
- https://vuldb.com/vuln/364435/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://github.com/opensourcepos/opensourcepos/commit/def0c27a0e252668df8d942fc31e16d1edfd7323 | patch | |
| https://github.com/opensourcepos/opensourcepos/pull/4545 | issue-trackingpatch | |
| https://github.com/opensourcepos/opensourcepos/security/advisories/GHSA-xq63-3v4g-39r5 | broken-link | |
| https://vuldb.com/submit/802559 | third-party-advisory | |
| https://vuldb.com/vuln/364435 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/364435/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.