Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "xsell_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
e107 Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-2099)
Oracle Application Server CVE-2006-3706 Vulnerability (CVE-2006-3706)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-5106)
WordPress Plugin Premium SEO Pack Multiple Vulnerabilities (1.8.0)