Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Plone CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5492)
WordPress Plugin Register IPs Unspecified Vulnerability (1.8.0)
MySQL CVE-2016-0667 Vulnerability (CVE-2016-0667)
WordPress Plugin 404page-your smart custom 404 error page Cross-Site Request Forgery (10.3)