Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "email_templates_key" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Liferay Portal Missing Authorization Vulnerability (CVE-2022-38512)
Django Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-31542)
WordPress Plugin Membership 2 Unspecified Vulnerability (4.0.0.2)
WordPress Plugin Custom Dashboard & Login Page-AGCA Multiple Unspecified Vulnerabilities (1.5.4.2)