A vulnerability labeled as problematic has been found in Ultimate Fosters Ultimate POS up to 7.2. This issue affects some unknown processing of the component Account Creation. The manipulation of the argument first-name results in cross site scripting.

This vulnerability is identified as CVE-2026-70560. The attack can be executed remotely. There is not any exploit available.