Wallaceit develops WallacePOS, a point-of-sale system, where vulnerabilities cluster around web-application input handling and file-management controls including cross-site scripting, cross-site request forgery, and unrestricted file uploads. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wallaceit over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3959HIGH Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | Jul 31, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-3960HIGH Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file. | Jul 31, 2019 | 7.2 | 23 | NO | NO |
CVE-2017-7388MEDIUM A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the 'wallacepos- | Apr 1, 2017 | 6.1 | 22 | NO | NO |
CVE-2019-3958MEDIUM Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks via a crafted sales transactio | Jul 31, 2019 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wallaceit.
Media articles that mention a CVE ID that affects a product developed by Wallaceit — matched by CVE ID, not by vendor name.