Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Apache Tomcat Improper Input Validation Vulnerability (CVE-2014-0033)
Jenkins Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2021-21615)
MediaWiki CVE-2021-42049 Vulnerability (CVE-2021-42049)
Magento CVE-2019-8091 Vulnerability (CVE-2019-8091)
WordPress Plugin YITH WooCommerce Cart Messages Security Bypass (1.4.3)