Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_delivery_terms_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
PostgreSQL Improper Authentication Vulnerability (CVE-2009-3231)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3747)
Atlassian Jira CVE-2020-36286 Vulnerability (CVE-2020-36286)
WordPress Plugin Blue Admin Cross-Site Request Forgery (21.06.01)
WordPress Plugin Custom 404 Pro Cross-Site Scripting (3.2.7)