What is CVE-2026-70560?
CVE-2026-70560 is a stored cross-site scripting vulnerability in Ultimate POS (Stock Management & Point of Sale) that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup via the user first-name field during account creation. It poses a risk of malicious code execution within the application context, affecting system integrity.
Azərbaycanca: CVE-2026-70560, Ultimate POS (Stock Management & Point of Sale) sistemində aşkarlanmış saxlanılan XSS zəifliyidir. Bu, aşağı səlahiyyətli autentifikasiya olunmuş hücumçulara hesab yaradarkən istifadəçinin ad sahəsinə zərərli HTML/script yerləşdirməyə imkan verir. Zəiflikdən qorunmaq üçün daxiletmələrin sanitizasiyası təmin edilməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
How can CVE-2026-70560 be exploited in the Ultimate POS system?
The vulnerability can be exploited by a low-privileged authenticated attacker injecting malicious HTML/script code into the user first-name field during account creation.
What is the primary mitigation for CVE-2026-70560?
To mitigate this vulnerability, sanitization of user inputs must be ensured.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.