Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "stock_delivery_terms_text[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Oracle Application Server Other Vulnerability (CVE-2004-2244)
WordPress Plugin Beaver Builder-WordPress Page Builder Security Bypass (1.7)
WordPress Plugin ARPrice-Responsive Pricing Table Cross-Site Request Forgery (2.3)
WordPress Plugin Invite Anyone PHP Object Injection (1.3.18)
WordPress Plugin AGP Font Awesome Collection Cross-Site Scripting (2.7.2)