CVE-2025-41011Disclosure(phppointofsale / php_point_of_sale)

LOWCVSS 6.1 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validation of user input by sending a request to '/reports/generate/specific_customer', ussing 'start_date_formatted' y 'end_date_formatted' parameters.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • php_point_of_sale

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Disclouser: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
php_point_of_sale

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-21: 4Technical Details · 2026-04-21: 404-21
Signal classification2 categories
Disclosure
375.0%
Disclouser
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Inyección SQL en Zeon Academy Pro de #ZeonGlobalTech #CVE CVE-2025-41011 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/inyeccion-sql-en-zeon-academy-pro-de-zeon-global-tech #AvisosDeSeguridad #TI #CNA #0day

    Post summary

    The tweet announces a new SQL injection vulnerability (CVE‑2025‑41011) affecting Zeon Academy Pro, without providing PoC, exploit, or patch details.

    01030703
    42.7K followersView on X
  • INCIBE-CERT@incibe_cert
    Disclouser

    ⚠️#INCIBEaviso | Inyección HTML en #PHPPointOfSale #CVE CVE-2025-41011 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/inyeccion-html-en-php-point-sale-0 #AvisosDeSeguridad #TI #CNA #0day

    Post summary

    The tweet announces an early alert for an HTML injection vulnerability (CVE-2025-41011) in PHP Point of Sale, providing minimal technical details but no PoC, exploit, or patch information.

    01020493
    42.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41011 HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validati… https://www.cve.org/CVERecord?id=CVE-2025-41011

    Post summary

    The post announces the HTML injection flaw (CVE‑2025‑41011) in PHP Point of Sale v19.4, detailing its technical nature but offering no exploit details or mitigations.

    00010155
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-41011 HTML injection vulnerability in PHP Point of Sale v19.4. This vulnerability allows an attacker to render HTML in the victim's browser due to a lack of proper validati… https://www.cve.org/CVERecord?id=CVE-2025-41011 ----- Traducción: CVE-2025-41011 vul… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2025‑41011, an HTML injection flaw in PHP Point of Sale v19.4 that permits arbitrary HTML rendering, but provides no PoC, exploit, active exploitation claim, or patch information.

    00000203
    72 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appphppointofsalephp_point_of_sale19.4--

Explore more