cvedb.io
CVE-2025-63800
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2025-11-18T16:15:46.310 · Last modified 2026-06-17T09:53:30.290

Summary

The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.

Affected products

opensourcepos — open_source_point_of_sale

Does this affect you?

Add your gear to cvedb and we'll alert you only when opensourcepos ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.