CVE-2026-33730Disclosure(opensourcepos / open_source_point_of_sale)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an authenticated low-privileged user to access the password change functionality of other users, including administrators, by manipulating the `employee_id` parameter. The application does not verify object ownership or enforce authorization checks. Version 3.4.2 adds object-level authorization checks to validate that the current user owns the employee_id being accessed.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open_source_point_of_sale

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
open_source_point_of_sale

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-27: 203-27
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-33730 Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Dir… https://www.cve.org/CVERecord?id=CVE-2026-33730

    Post summary

    The snippet briefly references CVE‑2026‑33730 for Open Source Point of Sale, noting an insecure directory pre‑3.4.2, but provides no PoC, exploit, patch, or active exploitation information.

    00000113
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33730 📊 Severity: 6.5 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33730 #CVE-2026-33730 #CVE #Medium #CyberSecurity #InfoSec https://t.co/mgdjphC4AJ

    Post summary

    The tweet merely announces the existence of CVE-2026‑33730 and notes its moderate severity, without providing technical, exploitation, or mitigation details.

    0000028
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensourceposopen_source_point_of_sale---

Explore more