Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-34466)
Sqlite Out-of-bounds Read Vulnerability (CVE-2021-31239)
Ruby Numeric Errors Vulnerability (CVE-2009-1904)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-2729)
WordPress Plugin Recart-The New GhostMonitor Unspecified Vulnerability (1.5.0)