CVE-2025-63800
HIGHDescription
The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or leaves the `password` and `repeat_password` parameters empty in the password change request, the backend still returns a successful response and sets the password to an empty string. This effectively disables authentication and may allow unauthorized access to user or administrative accounts.
Is your site exposed to CVE-2025-63800?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| opensourcepos | open_source_point_of_sale |
References
Frequently Asked Questions
What is CVE-2025-63800? +
How severe is CVE-2025-63800? +
What products are affected by CVE-2025-63800? +
How do I check if I'm vulnerable to CVE-2025-63800? +
Related Vulnerabilities
No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console …
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After …
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through …
Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 …
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any …
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. Once access is gained either by default, common, or …