| Version | Supported |
|---|---|
| latest | ✅ |
If you find a security vulnerability in FinOpenPOS, do not open a public issue.
Instead, email joaohenriquebarbosa21@gmail.com with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
You will receive a response within 72 hours acknowledging receipt.
Relevant vulnerabilities include:
- Authentication or authorization bypass
- SQL injection or data exposure
- Certificate or private key leakage in the fiscal engine
- XML injection or fiscal data manipulation
- Cross-site scripting (XSS) or CSRF
- Receipt: acknowledgment within 72h
- Triage: severity assessment
- Fix: patch developed in a private branch
- Release: patched version published
- Disclosure: public advisory after fix is available