Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "title" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
OpenSSL Numeric Errors Vulnerability (CVE-2016-2106)
WordPress Plugin Simple Fields Cross-Site Scripting (1.4.10)
WordPress Plugin Erident Custom Login and Dashboard Cross-Site Request Forgery (3.4.1)
PHP NULL Pointer Dereference Vulnerability (CVE-2018-10548)
WordPress Plugin WHOIS 'domain' Parameter Cross-Site Scripting (1.4.2.2)