CVE-2026-39380 | opensourcepos Open Source Point of Sale up to 3.4.2 Employees Interface stock_location cross site scripting (GHSA-7hg5-68rx-xpmg)
A vulnerability classified as problematic has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is an unknown function of the component Employees Interface. This manipulation of the argument stock_location causes cross site scripting.
This vulnerability is handled as CVE-2026-39380. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.