Alphabug

9 exploits Active since Sep 2025
CVE-2025-10026 WRITEUP LOW WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/-complex_header.php. The manipulation of the argument scripts results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used.
CVSS 3.5
CVE-2025-10027 WRITEUP LOW WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown functionality of the file /inventory/main/vendors/datatables/unit_testing/templates/2512.php. This manipulation of the argument scripts causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVSS 3.5
CVE-2025-10028 WRITEUP LOW WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This affects an unknown part of the file /inventory/main/vendors/datatables/unit_testing/templates/6776.php. Such manipulation of the argument scripts leads to cross site scripting. The attack can be launched remotely. The exploit is publicly available and might be used.
CVSS 3.5
CVE-2025-10029 WRITEUP LOW WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/complex_header_2.php. Performing manipulation of the argument scripts results in cross site scripting. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
CVSS 3.5
CVE-2025-10063 WRITEUP MEDIUM WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A vulnerability was identified in itsourcecode POS Point of Sale System 1.0. This vulnerability affects unknown code of the file /inventory/main/vendors/datatables/unit_testing/templates/deferred_table.php. The manipulation of the argument scripts leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
CVSS 4.3
CVE-2025-10064 WRITEUP MEDIUM WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A security flaw has been discovered in itsourcecode POS Point of Sale System 1.0. This issue affects some unknown processing of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_two_headers.php. The manipulation of the argument scripts results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be exploited.
CVSS 4.3
CVE-2025-10065 WRITEUP MEDIUM WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A weakness has been identified in itsourcecode POS Point of Sale System 1.0. Impacted is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dom_data_th.php. This manipulation of the argument scripts causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
CVSS 4.3
CVE-2025-10066 WRITEUP MEDIUM WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A security vulnerability has been detected in itsourcecode POS Point of Sale System 1.0. The affected element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/dymanic_table.php. Such manipulation of the argument scripts leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
CVSS 4.3
CVE-2025-10067 WRITEUP MEDIUM WRITEUP
Facebook-kimmymatillano Point OF Sale System - Code Injection
A vulnerability was detected in itsourcecode POS Point of Sale System 1.0. The impacted element is an unknown function of the file /inventory/main/vendors/datatables/unit_testing/templates/empty_table.php. Performing manipulation of the argument scripts results in cross site scripting. It is possible to initiate the attack remotely. The exploit is now public and may be used.
CVSS 4.3