Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "email_templates_key" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Track That Stat 'data' Parameter Cross-Site Scripting (1.0.8)
Oracle Database Server CVE-2018-3004 Vulnerability (CVE-2018-3004)
WordPress Plugin Form Vibes-Database Manager for Forms SQL Injection (1.4.10)
MySQL CVE-2021-2339 Vulnerability (CVE-2021-2339)
PHP Improper Encoding or Escaping of Output Vulnerability (CVE-2024-5585)