| Summary | An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of Sale (POS) interface for every operator who selects that customer. |
|---|---|
| Publication Date | June 4, 2026, 4:16 a.m. |
| Registration Date | June 5, 2026, 4:10 a.m. |
| Last Update | June 5, 2026, 12:23 a.m. |