Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Download Manager Multiple Security Bypass Vulnerabilities (2.6.92)
Oracle JRE CVE-2013-0438 Vulnerability (CVE-2013-0438)
WordPress Plugin YITH Maintenance Mode Multiple Cross-Site Scripting Vulnerabilities (1.3.8)
WordPress Plugin Cherry Services List Information Disclosure (1.4.1)