CVE-2026-32712 | opensourcepos Open Source Point of Sale up to 3.4.2 Daily Sales Page customer_name first_name/last_name cross site scripting
A vulnerability classified as problematic was found in opensourcepos Open Source Point of Sale up to 3.4.2. The affected element is the function customer_name of the component Daily Sales Page. Such manipulation of the argument first_name/last_name leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-32712. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.