Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "PACKING_SLIPS_SUMMARY_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin UnGallery Local File Disclosure (1.5.8)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-6125)
WordPress Plugin EZ SQL Reports Shortcode Widget and DB Backup Multiple Vulnerabilities (4.11.33)
WordPress Plugin Chat Room Directory Traversal (0.1.2)
WordPress Plugin Photo Gallery by Supsystic Multiple Vulnerabilities (1.8.5)