Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "SHIPPING_GENDER_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
TYPO3 Improper Input Validation Vulnerability (CVE-2011-4904)
WordPress Plugin Gantry 4 Framework Cross-Site Scripting (4.1.5)
WordPress Plugin Multi Step Form Multiple Cross-Site Scripting Vulnerabilities (1.2.5)
WordPress Plugin BigDoor Quick Gamification for WordPress Cross-Site Scripting (1.0.5)