Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_delivery_terms_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-2000-1090)
PHP Improper Input Validation Vulnerability (CVE-2016-3185)
Craft CMS CVE-2025-32432 Vulnerability (CVE-2025-32432)
WordPress Plugin Flat Preloader Cross-Site Request Forgery (1.5.3)
Oracle Database Server CVE-2016-5555 Vulnerability (CVE-2016-5555)