High severity8.8NVD Advisory· Published Oct 31, 2022· Updated Jun 17, 2026
CVE-2022-40291
CVE-2022-40291
Description
The application was vulnerable to Cross-Site Request Forgery (CSRF) attacks, allowing an attacker to coerce users into sending malicious requests to the site to delete their account, or in rare circumstances, hijack their account and create other admin accounts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:phppointofsale:php_point_of_sale:19.0:*:*:*:*:*:*:*
- PHP Point of Sale LLC/PHP Point of Salev5Range: 0
Patches
Vulnerability mechanics
References
1- www.themissinglink.com.au/security-advisories/cve-2022-40291nvdThird Party Advisory
News mentions
0No linked articles in our index yet.