Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "specials_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
PHP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2022-31628)
Apache 2.x version older than 2.0.49
Apache Tomcat Improper Input Validation Vulnerability (CVE-2013-2185)
MySQL CVE-2020-14539 Vulnerability (CVE-2020-14539)
PostgreSQL Uncontrolled Search Path Element Vulnerability (CVE-2020-14349)