Impact
money‑pos 1.0 contains a stored Cross‑Site Scripting vulnerability in the goodsName parameter. The backend concatenates the unfiltered goodsName directly into the order log description, which the frontend renders through v-html. An attacker who can create products can inject malicious JavaScript that executes in the browser context of an administrator when the order logs are viewed. This enables session theft, defacement, or further lateral actions within the application.
Affected Systems
The affected product is money‑pos version 1.0. No other vendor, product, or version details are provided, and the flaw appears only in this release.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% shows a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the attacker must have product‑creation privileges and the target is an administrator viewing the logs, the attack is feasible in environments with inadequate access controls. Although exploitation likelihood is low, the potential impact on admin sessions and the overall system justifies prompt remediation.
OpenCVE Enrichment