CVE-2022-40295

MEDIUM

Phppointofsale Php Point OF Sale - Information Disclosure

Title source: rule
STIX 2.1

Description

The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.

Scores

CVSS v3 4.9
EPSS 0.0013
EPSS Percentile 32.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-916 CWE-311
Status published
Products (1)
phppointofsale/php_point_of_sale 19.0
Published Oct 31, 2022
Tracked Since Feb 18, 2026