Skip to content

Security: Ohryzon/FinOpenPOS

Security

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you find a security vulnerability in FinOpenPOS, do not open a public issue.

Instead, email joaohenriquebarbosa21@gmail.com with:

  1. Description of the vulnerability
  2. Steps to reproduce
  3. Potential impact
  4. Suggested fix (if any)

You will receive a response within 72 hours acknowledging receipt.

Scope

Relevant vulnerabilities include:

  • Authentication or authorization bypass
  • SQL injection or data exposure
  • Certificate or private key leakage in the fiscal engine
  • XML injection or fiscal data manipulation
  • Cross-site scripting (XSS) or CSRF

Process

  1. Receipt: acknowledgment within 72h
  2. Triage: severity assessment
  3. Fix: patch developed in a private branch
  4. Release: patched version published
  5. Disclosure: public advisory after fix is available

There aren't any published security advisories