CVE-2025-67263
Last modified
CVE-2025-67263 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-supplied input stored in the Name and Surname fields. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-supplied input stored in the Name and Surname fields. An attacker can insert malicious HTML or script content into these fields, which, persisted in the database.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Abacre | Retail Point Of Sale | 14.0.0.396 |
References
- https://packetstorm.news/files/id/214045/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67263?
How severe is CVE-2025-67263?
How do I fix CVE-2025-67263?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67254NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Direct…7.5
- CVE-2025-67255In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameter…8.8
- CVE-2025-67259A Broken Access Control vulnerability exists in ClassroomIO …6.5
- CVE-2025-6726The Block Editor Gallery Slider plugin for WordPress is vuln…4.3
- CVE-2025-67260The Terrapack software, from ASTER TEC / ASTER S.p.A., with …8.8
- CVE-2025-67261Abacre Retail Point of Sale 14.0.0.396 is vulnerable to cont…6.5
- CVE-2025-67264An OS command injection vulnerability in the com.sprd.engine…7.8
- CVE-2025-67268gpsd before commit dc966aa contains a heap-based out-of-boun…9.8
- CVE-2025-67269An integer underflow vulnerability exists in the `nextstate(…7.5
- CVE-2025-67274An issue in continuous.software aangine v.2025.2 allows a re…7.5
- CVE-2025-67278An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW befor…6.5
- CVE-2025-67279An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW befor…5.3
Are you affected by CVE-2025-67263?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
