Home

Description

Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.

PUBLISHED Reserved 2026-01-18 | Published 2026-02-01 | Updated 2026-02-02 | Assigner VulnCheck




MEDIUM: 5.1CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
MEDIUM: 6.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Problem types

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

4.4
affected

Credits

Vulnerability-Lab [Research Team] finder

References

www.vulnerability-lab.com/get_content.php?id=2296 (Vulnerability Lab Advisory) exploit

ultimatefosters.com/docs/ultimatepos/ (Product Homepage) product

www.vulncheck.com/...t-cross-site-scripting-via-product-name (VulnCheck Advisory: Ultimate POS 4.4 Persistent Cross-Site Scripting via Product Name) third-party-advisory

cve.org (CVE-2021-47908)

nvd.nist.gov (CVE-2021-47908)

Download JSON