CVE-2025-63800 — The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty string due to missing server-side validation. When an authenticated user omits or — CVE Database · The Intelligence Room