CVE-2026-70560
Received Received - Intake

Stored XSS in Ultimate POS Stock Management Software

Vulnerability report for CVE-2026-70560, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: VulnCheck

Description

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user first-name field during account creation. Attackers with a low-privileged role such as Cashier can submit a leave request through the HRM/Leave module, causing the unsanitized first-name markup to execute in the browser session of any higher-privileged user who views the leave-application notification pane, enabling cross-user session compromise within the admin origin.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thewebfosters ultimate_pos to 7.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in Ultimate POS v7.2 and earlier versions. It allows low-privileged authenticated attackers to inject malicious HTML or script markup by setting a malicious payload in the user first-name field during account creation. When a higher-privileged user views a leave request notification for the affected user, the injected script executes in their browser session, enabling session compromise within the admin origin.

Detection Guidance

To detect this vulnerability, inspect user accounts in Ultimate POS for suspicious first names containing HTML or script tags. Check the HRM/Leave module notifications for any rendered malicious scripts. Review server logs for unusual leave request activities or unauthorized account creations.

Impact Analysis

Attackers with low privileges, such as Cashiers, can exploit this flaw to inject scripts that execute in the sessions of higher-privileged users like administrators. This could lead to session hijacking, unauthorized access to sensitive data, or further compromise of the application or system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations using affected versions may face compliance violations, data breaches, and potential legal consequences.

Mitigation Strategies

Immediately update Ultimate POS to the latest version (7.2 or later). Sanitize all user input fields, especially the first name, to prevent XSS payloads. Restrict low-privileged users from creating accounts without admin approval. Monitor HRM/Leave module notifications for any signs of script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-70560. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart