Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "tracking_number" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin My Calendar Multiple Cross-Site Scripting Vulnerabilities (1.10.1)
WebLogic CVE-2016-3445 Vulnerability (CVE-2016-3445)
MySQL CVE-2015-2617 Vulnerability (CVE-2015-2617)
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-28735)
WordPress Plugin Custom 404 Pro Unspecified Vulnerability (3.7.0)