CVE-2025-56382
MEDIUMLionCoders SalePro POS 5.4.8 - Authenticated Stored Cross-Site Scripting via Customer Name Parameter
Title source: llmDescription
A stored Cross-site scripting (XSS) vulnerability exists in the Customer Management Module of LionCoders SalePro POS 5.4.8. An authenticated attacker can inject arbitrary web script or HTML via the 'Customer Name' parameter when creating or editing customer profiles. This malicious input is improperly sanitized before storage and subsequent rendering, leading to script execution in the browsers of users who view the affected customer details.
References (2)
Core 2
Core References
Third Party Advisory
https://github.com/Auspicious-Rook/Vulnerability-Research/tree/main/CVE-2025-56382
Scores
CVSS v3
6.1
EPSS
0.0022
EPSS Percentile
12.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
lion-coders/salepro_pos
5.4.8
Published
Oct 06, 2025
Tracked Since
Feb 18, 2026