Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "formats_titles[7]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Podcast Channels Cross-Site Scripting (0.20)
WordPress Plugin Count per Day Cross-Site Request Forgery (3.2.5)
WordPress Plugin WP Custom Admin Interface PHP Object Injection (7.28)
WordPress Plugin Contact Form 7 Datepicker Cross-Site Scripting (2.6.0)
Moodle Insertion of Sensitive Information into Log File Vulnerability (CVE-2018-10889)