Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tax_class_title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
MediaWiki Insertion of Sensitive Information into Log File Vulnerability (CVE-2018-0504)
WordPress Plugin Job Manager Multiple Cross-Site Scripting Vulnerabilities (0.7.18)
WordPress Plugin Resize Image After Upload Cross-Site Request Forgery (1.8.5)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-9481)