Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_indication_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Access Manager Multiple Vulnerabilities (6.6.1)
Magento XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2021-21019)
Sqlite Use After Free Vulnerability (CVE-2021-20227)
WordPress Plugin Widget Logic Cross-Site Request Forgery (5.9.0)
TYPO3 Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-0815)