Impact
A flaw in the Login Endpoint Filters.php index in Open Source Point of Sale up to version 3.4.2 allows an attacker to bypass the normal restriction on authentication attempts. The vulnerability creates a path for excessive login retries, enabling brute‑force efforts that could compromise accounts or exhaust resources. The issue stems from improper authentication controls (CWE‑307) and insufficient error handling (CWE‑799), and its exploit is publicly available and identified as high‑complexity but difficult to execute.
Affected Systems
The affected product is opensourcepos Open Source Point of Sale, specifically any installation using version 3.4.2 or earlier. No further version data is supplied, so users of older releases should review their deployment for this vulnerability.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity risk, and the EPSS score is not reported, suggesting limited publicly known exploitation activity. Because the attack can be launched remotely and requires high complexity, the likelihood of exploitation is considered moderate. The vulnerability is not listed in CISA’s KEV catalog. Without an official patch, the risk relies on the ability to mitigate brute‑force attempts through configuration or custom code.
OpenCVE Enrichment