Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_manual_name_long[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
MySQL CVE-2017-10286 Vulnerability (CVE-2017-10286)
WordPress Plugin Tidio Gallery Multiple Vulnerabilities (1.1)
PHP Out-of-bounds Write Vulnerability (CVE-2016-7126)
Oracle JRE CVE-2018-2678 Vulnerability (CVE-2018-2678)
WordPress Plugin Essential Grid Portfolio-Photo Gallery Security Bypass (1.1.2)