Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "configuration_title[1][MODULE_SHIPPING_PERCENT_TEXT_TITLE]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.6.x Security Bypass (1.6.0 - 1.6.6)
Atlassian Jira CVE-2020-29451 Vulnerability (CVE-2020-29451)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-5379)
Jboss EAP Server-Side Request Forgery (SSRF) Vulnerability (CVE-2018-14721)
PHP Insufficient Verification of Data Authenticity Vulnerability (CVE-2024-5458)