Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-3220 Vulnerability (CVE-2012-3220)
Internet Information Services Other Vulnerability (CVE-2002-0075)
WordPress Plugin Party Hall Booking Manager SQL Injection (1.1)
phpMyFAQ Other Vulnerability (CVE-2005-3734)
WordPress Plugin SEO Redirection-301 Redirect Manager SQL Injection (3.5)