Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "countries_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2009-1015 Vulnerability (CVE-2009-1015)
WordPress Plugin Smash Balloon Social Post Feed Security Bypass (4.0)
WordPress Plugin Integrator 'redirect_to' Parameter Cross-Site Scripting (1.32)
PostgreSQL Numeric Errors Vulnerability (CVE-2010-0733)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-2146)