CVE-2026-337301
Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter framework. Prior to version 3.4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows an authenticated low-privileged user to access the password change functionality of other users, including administrators, by manipulating the employee_id parameter. The application does not verify object ownership or enforce authorization checks.
Version 3.4.2 adds object-level authorization checks to validate that the current user owns the employee_id being accessed.
- Public exploit or PoC is available
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N- 27 Mar 2026Published to NVD
- 01 Apr 2026Last modified
Public Exploits & PoCs
1ATT&CK techniques
1Techniques this CVE enables - linked via CWE → CAPEC → ATT&CK. Pills with a solid outline are named directly in ATT&CK or Nuclei templates (high confidence); the others are linked through weakness mappings.
▤ Build a SIEM detection for these techniques