Impact
The vulnerability is a stored cross‑site scripting flaw that allows authenticated attackers with a low‑privileged role, such as a cashier, to inject arbitrary HTML and script markup. By entering a malicious payload into the first‑name field when creating a user account, the attacker can cause this payload to be stored and rendered unfiltered. When a higher‑privileged user views the leave‑application notification pane, the unsanitized markup executes in their browser, enabling cross‑user session compromise within the admin origin.
Affected Systems
Ultimate POS (Stock Management & Point of Sale) by Ultimate Fosters is affected. The vulnerability applies to all installations that allow account creation with a first‑name field and use the HRM/Leave module to submit leave requests. No specific version information is provided, so all variants of the application may be vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path requires the attacker to have a valid low‑privileged account, create a user with a malicious first‑name, and then trigger the HRM/Leave module to display the unsanitized input. Once executed, the attacker can hijack sessions of higher‑privileged users who view the notification pane.
OpenCVE Enrichment