CVE-2026-70560: Ultimate POS Stored XSS via First Name Field in Leave Notifications
Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attackers to inject arbitrary HTML and script markup by setting a malicious payload in the user first-name field during account creation. Attackers with a low-privileged role such as Cashier can submit a leave request through the HRM/Leave module, causing the unsanitized first-name markup to execute in the browser session of any higher-privileged user who views the leave-application notification pane, enabling cross-user session compromise within the admin origin.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70560?
CVE-2026-70560 has a severity rating of medium, with a score of 5.4.
How do I fix CVE-2026-70560?
To fix CVE-2026-70560, ensure proper input validation and sanitization of the first-name field in user accounts.
What type of vulnerability is CVE-2026-70560?
CVE-2026-70560 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-70560?
Low-privileged authenticated users of Ultimate POS can potentially exploit CVE-2026-70560.
What impact does CVE-2026-70560 have on users?
CVE-2026-70560 allows attackers to inject arbitrary HTML and script markup, which can compromise the security of user sessions.