Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Python Out-of-bounds Read Vulnerability (CVE-2019-15903)
WordPress Plugin Duplicator-WordPress Migration Unspecified Vulnerability (1.1.34)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-2922)
Moodle Incorrect Default Permissions Vulnerability (CVE-2012-1157)