Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "company_address" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
WordPress Plugin YITH WooCommerce Added to Cart Popup Security Bypass (1.3.11)
WordPress Plugin Pods-Custom Content Types and Fields SQL Injection (2.5.1.1)
WordPress Plugin Menu Swapper Cross-Site Request Forgery (1.1.0.2)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More Unspecified Vulnerability (2.11.0)