Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "xsell_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Zingiri Web Shop Unspecified Vulnerability (2.6.5)
Liferay DXP Incorrect Default Permissions Vulnerability (CVE-2022-42130)
Apache HTTP Server Incorrect Calculation of Buffer Size Vulnerability (CVE-2004-0940)
Nexus Repository Manager Improper Authentication Vulnerability (CVE-2019-9629)