Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tracking_number" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2015-0483 Vulnerability (CVE-2015-0483)
PHP CVE-2007-5898 Vulnerability (CVE-2007-5898)
WordPress Clickjacking Vulnerability (0.7 - 3.1.2)
WordPress Plugin WP Statistics Multiple Cross-Site Scripting Vulnerabilities (12.0.1)
WordPress Plugin Verse-O-Matic Cross-Site Request Forgery (4.1.1)