Description

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.

INFO

Published Date :

2025-11-18T00:00:00.000Z

Last Modified :

2025-11-18T17:08:08.461Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-63800 vulnerability.

Vendors Products
Opensourcepos
  • Open Source Point Of Sale
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-63800.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact