Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_delivery_terms_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2023-21937 Vulnerability (CVE-2023-21937)
WordPress Plugin Splashing Images Multiple Vulnerabilities (2.1)
WordPress Plugin Sign-up Sheets Cross-Site Scripting (1.0.13)
WordPress 3.9.x Multiple Vulnerabilities (3.9 - 3.9.19)
WordPress Plugin Social Media Widget by Acurax Multiple Unspecified Vulnerabilities (3.2.3)