Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.
History

Sun, 01 Feb 2026 12:30:00 +0000

Type Values Removed Values Added
Description Ultimate POS 4.4 contains a persistent cross-site scripting vulnerability in the product name parameter that allows remote attackers to inject malicious scripts. Attackers can exploit the vulnerability through product add or edit functions to execute arbitrary JavaScript and potentially hijack user sessions.
Title Ultimate POS 4.4 Persistent Cross-Site Scripting via Product Name
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-01T12:15:46.656Z

Reserved: 2026-01-18T12:35:05.177Z

Link: CVE-2021-47908

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-01T13:15:54.727

Modified: 2026-02-01T13:15:54.727

Link: CVE-2021-47908

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.