Unrated severityNVD Advisory· Published Nov 18, 2025· Updated Nov 18, 2025
CVE-2025-63800
CVE-2025-63800
Description
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the password and repeat_password parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.
Affected products
2- Open Source Point of Sale/Open Source Point of Saledescription
- Range: =3.4.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.