Critical severity9.0NVD Advisory· Published Oct 31, 2022· Updated Jun 17, 2026
CVE-2022-40288
CVE-2022-40288
Description
The application was vulnerable to an authenticated Stored Cross-Site Scripting (XSS) in the user profile data fields, which could be leveraged to escalate privileges within and compromise any account that views their user profile.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- PHP Point of Sale LLC/PHP Point of Salev5Range: 0
Patches
Vulnerability mechanics
References
1- www.themissinglink.com.au/security-advisories/cve-2022-40288nvdThird Party Advisory
News mentions
0No linked articles in our index yet.