Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "featured_type_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
Remediation
References
Related Vulnerabilities
Jenkins Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2023-35141)
PostgreSQL Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-1115)
MySQL CVE-2015-4836 Vulnerability (CVE-2015-4836)
WordPress Plugin CM Ad Changer Cross-Site Scripting (1.7.7)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-6102)