Open Source Point of Sale (opensourcepos), a PHP/CodeIgniter-based web POS application, contains a CSRF vulnerability in its filter configuration affecting versions 3.4.0 through 3.4.1 (fixed in 3.4.2). The application’s CSRF protection was explicitly disabled in the filter configuration (notably in app/Config/Filters.php), allowing state-changing POST requests to be processed without validating a CSRF token. An attacker can host a malicious page that triggers a victim administrator’s browser (while authenticated to opensourcepos) to submit unauthorized requests, enabling silent creation of a new Administrator account with full privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
app/Config/Filters.php by uncommenting/enabling the CSRF protection line. This is not recommended as a standalone measure without the full 3.4.2 patch because it may break functionality (noted risk of Sales module issues due to token synchronization).Patch, then assume compromise.
app/Config/Filters.php and adjusts CSRF token regeneration settings to address associated AJAX/token synchronization issues (race conditions).1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository documents a critical CSRF vulnerability (CVE-2025-68434) in OpenSourcePOS versions 3.4.0 and 3.4.1, where global CSRF protection was disabled in the application's configuration. The exploit leverages a crafted HTML form that, when loaded in a victim administrator's browser, silently submits a POST request to the employee creation endpoint, resulting in the creation of a new administrator account with full privileges. The repository contains only documentation (README.md) and a placeholder for a PoC file, but the README provides a detailed description of the exploit scenario, the vulnerable configuration, and the exact payload used. The main attack vector is browser-based CSRF, requiring social engineering to lure an authenticated admin to the attacker's page. The only fingerprintable endpoint is the employee creation URL on the target OpenSourcePOS instance. No actual exploit code is present in the repository, but the exploit is fully described and reproducible from the documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.