Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "countries_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Analytics Dashboard SQL Injection (2.0.4)
WordPress Plugin FCChat Widget 'Upload.php' Arbitrary File Upload (2.2.13.1)
WordPress Plugin Brizy-Page Builder Security Bypass (2.4.44)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-28566)