CVE-2025-66923 | Open Source Point of Sale 3.4.1 Customer phone_number cross site scripting
A vulnerability, which was classified as problematic, was found in Open Source Point of Sale 3.4.1. Affected by this vulnerability is an unknown functionality of the component Customer Handler. The manipulation of the argument phone_number results in cross site scripting.
This vulnerability is identified as CVE-2025-66923. The attack can be executed remotely. There is not any exploit available.