A vulnerability labeled as problematic has been found in Ultimate Fosters Ultimate POS up to 7.2. This issue affects some unknown processing of the component Account Creation. The manipulation of the argument first-name results in cross site scripting. This vulnerability is identified as CVE-2026-70560. The attack can be executed remotely. There... Weiterlesen
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-70560 | Ultimate Fosters Ultimate POS up to 7.2 Account Creation first-name cross site scripting
A vulnerability labeled as problematic has been found in Ultimate Fosters Ultimate POS up to 7.2. This issue affects some unknown processing of the component Account Creation. The manipulation of the argument first-name results in cross…
Reagiere als Erste:r — dein Feedback zählt!
2. Cyber Threat Intelligence & Forensik
IoC Intelligence (1 Indikatoren)
CVE-2026-70560
Exploit & Remediation Lifecycle Timeline
CVE-2026-70560Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Öffentlicher Nachweis/Code verfügbar (Exploit-DB/EUVD)
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & Public PoC Radar
ELEVATED · Index 15/100Exploit-DB
Kein EDB-EintragInteraktion
Interaktion nötigAuthentifizierung
Erforderlich3. Compliance, SLA & Vendor Adherence
CISA-SSVC-Triage (vulnrichment)CVE-2026-70560
Exploitation: poc (PoC verfügbar)Automatable: no (Nicht automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2026-08-12T12:27:19.075649Z · CISA Coordinator
Advisory Radar
Workaround & Virtual-Patching empfohlen
Hersteller-Sicherheitsmeldungen & Patch-Status
Handlungsempfehlung für Administratoren
Öffentliche PoCs existieren. Isolieren Sie das System oder wenden Sie Micro-Segmentierungsregeln an, bis offizielle Patches vorliegen.
Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
-
Web Referencecodecanyon.net
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
1 öffentliche Exploit-Referenz(en) detektiert (VulnCheck Exploit Intelligence).
PoC einsehen