Impact
money‑pos 1.0 includes a stored Cross‑Site Scripting vulnerability in the goodsName parameter. The backend concatenates the unfiltered value directly into the order log description, which the frontend renders through v-html. An attacker who can create products can inject malicious JavaScript that runs in the context of an administrator when the order logs are viewed, leading to complete code‑execution capabilities on the user’s browser. The impact is limited to the privileges of the entity viewing the logs – typically an administrator – but the payload can be used to steal session cookies, deface pages, or perform further actions on the system.
Affected Systems
The affected product is money‑pos version 1.0. No additional vendor or product information is listed, and no further version details are provided. The vulnerability exists only in this release of the application.
Risk and Exploitability
The vulnerability is a high‑severity stored XSS that allows code execution for privileged users. The EPSS score is not available, but the lack of protective escape mechanisms indicates a high likelihood of exploitation in environments where user input is reflected. The vulnerability is not noted in CISA KEV. Attackers would need product‑creation privileges; once achieved, they can embed malicious scripts that are executed the next time an administrator opens the order logs.
OpenCVE Enrichment