๐Ÿ” CVE Alert

CVE-2026-70560

MEDIUM 5.4

Ultimate POS Stored XSS via First Name Field in Leave Notifications

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user first-name field during account creation. Attackers with a low-privileged role such as Cashier can submit a leave request through the HRM/Leave module, causing the unsanitized first-name markup to execute in the browser session of any higher-privileged user who views the leave-application notification pane, enabling cross-user session compromise within the admin origin.

CWE CWE-79
Vendor ultimate fosters
Product ultimate pos (stock management & point of sale)
Published Aug 12, 2026
Last Updated Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for ultimate fosters ultimate pos (stock management & point of sale)

Be the first to know when new medium vulnerabilities affecting ultimate fosters ultimate pos (stock management & point of sale) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Ultimate Fosters / Ultimate POS (Stock Management & Point of Sale)
0 โ‰ค 7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
codecanyon.net: https://codecanyon.net/item/ultimate-pos-stock-management-point-of-sale-application/21216332 github.com: https://github.com/aaronamran/CVE-Disclosures/tree/main/CVE-2026/CVE-2026-70560 vulncheck.com: https://www.vulncheck.com/advisories/ultimate-pos-stored-xss-via-first-name-field-in-leave-notifications

Credits

Aaron Amran Bin Amiruddin