CVE-2022-40295

Severity CVSS v4.0:
Pending analysis
Type:
CWE-916 Use of Password Hash With Insufficient Computational Effort
Publication date:
31/10/2022
Last modified:
25/02/2026

Description

The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user passwords, which could lead to the compromise of plaintext passwords via offline attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phppointofsale:php_point_of_sale:19.0:*:*:*:*:*:*:*