OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE).
Metrics
Affected Vendors & Products
References
History
Tue, 24 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensourcepos open Source Point Of Sale
|
|
| CPEs | cpe:2.3:a:opensourcepos:open_source_point_of_sale:3.4.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensourcepos open Source Point Of Sale
|
Mon, 23 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-434 | |
| Metrics |
cvssV3_1
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensourcepos
Opensourcepos opensourcepos |
|
| Vendors & Products |
Opensourcepos
Opensourcepos opensourcepos |
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-02-20T00:00:00.000Z
Updated: 2026-02-23T20:12:05.206Z
Reserved: 2026-02-16T00:00:00.000Z
Link: CVE-2026-26746
Updated: 2026-02-23T20:11:02.756Z
Status : Analyzed
Published: 2026-02-20T17:25:55.920
Modified: 2026-02-24T20:42:28.327
Link: CVE-2026-26746
No data.