CVE-2019-3960: Wallaceit Wallacepos

High severity, CVSS 7.2. EPSS: 3% chance of exploitation in the next 30 days.

Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute arbitrary code by uploading a malicious PHP file.

Affected products

Published 2019-07-31. Last modified 2026-06-17.