A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4.8. An authenticated attacker can inject arbitrary web script or HTML via the 'Customer Name' parameter when creating or editing customer profiles. This malicious input is improperly sanitized before storage and subsequent rendering, leading to script execution in the browsers of users who view the affected customer details.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Oct 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Lioncoders
Lioncoders salepro Pos |
|
Vendors & Products |
Lioncoders
Lioncoders salepro Pos |
Mon, 06 Oct 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Mon, 06 Oct 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4.8. An authenticated attacker can inject arbitrary web script or HTML via the 'Customer Name' parameter when creating or editing customer profiles. This malicious input is improperly sanitized before storage and subsequent rendering, leading to script execution in the browsers of users who view the affected customer details. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-10-06T00:00:00.000Z
Updated: 2025-10-06T20:02:07.857Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56382

Updated: 2025-10-06T20:01:59.292Z

Status : Awaiting Analysis
Published: 2025-10-06T18:15:51.407
Modified: 2025-10-08T19:38:32.610
Link: CVE-2025-56382

No data.