CVE-2025-70093 | OpenSourcePOS 3.4.1 AJAX command injection
A vulnerability was found in OpenSourcePOS 3.4.1 and classified as problematic. Affected is an unknown function of the component AJAX Handler. Executing a manipulation can lead to command injection.
This vulnerability is handled as CVE-2025-70093. The attack can only be done within the local network. There is not any exploit available.
It is advisable to implement a patch to correct this issue.