Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin ThinkTwit Security Bypass (1.5.1)
WordPress Plugin Widget Logic Cross-Site Request Forgery (5.9.0)
phpMyAdmin CVE-2019-19617 Vulnerability (CVE-2019-19617)
Drupal Core 9.2.x Security Bypass (9.2.0 - 9.2.20)
WordPress Plugin Mingle Forum SQL Injection and Security Bypass Vulnerabilities (1.0.26)