Geng Yang[verified]@geng_zastDisclosure
The note highlights that CVE‑2026‑19895 lacks brute‑force protection and validates the CAPTCHA after password verification, exposing a server‑side oracle vulnerability.
ZAST AI[verified]@zast_aiGeneral
ZAST.AI confirms CVE-2026-19895 as a credential‑enumeration flaw in OpenSourcePOS 3.4.2 or earlier, rated CVSS 3.1: 5.3, with no PoC, exploit, or patch details provided.
CVE@CVEnewDisclosure
The post announces CVE-2026-19895, detailing a vulnerability in Open Source Point of Sale affecting the Login::index function up to version 3.4.2, with no PoC, exploit, or patch information provided.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑19895, a vulnerability in OpenSourcePOS versions up to 3.4.2, affecting the Login::index function in app/Config/Filters.php.