
CVE-2023-43725 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43725
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_products_status_name_long[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "orders_products_status_name_long[1]", lo que podría provocar ... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43724 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43724
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "derb6zmklgtjuhh2cn5chn2qjbm2stgmfa4.oastify.comscription[1][name]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "derb6zmklgtjuhh2cn5chn2qjbm2stg... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43723 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43723
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "orders_status_name[1]", lo que podría provocar la ejecución no autorizada d... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43722 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43722
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "orders_status_groups_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "orders_status_groups_name[1]", lo que podría provocar la ejecución n... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43721 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43721
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "PACKING_SLIPS_SUMMARY_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "PACKING_SLIPS_SUMMARY_TITLE[1]", lo que podría provocar la ejecuci... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43720 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43720
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "BILLING_GENDER_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "BILLING_GENDER_TITLE[1]", lo que podría provocar la ejecución no autoriza... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43719 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43719
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "SHIPPING_GENDER_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "SHIPPING_GENDER_TITLE[1]", lo que podría provocar la ejecución no autori... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43718 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43718
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "MSEARCH_ENABLE_TITLE[1]", lo que podría provocar la ejecución no autoriza... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43717 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43717
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "MSEARCH_HIGHLIGHT_ENABLE_TITLE[1]", lo que podría provocar la e... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-43716 – Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
https://notcve.org/view.php?id=CVE-2023-43716
30 Sep 2023 — Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "MAX_DISPLAY_NEW_PRODUCTS_TITLE[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. Os Commerce es actualmente susceptible a una vulnerabilidad de Cross-Site Scripting (XSS). Esta vulnerabilidad permite a los atacantes inyectar JS a través del parámetro "MAX_DISPLAY_NEW_PRODUCTS_TITLE[1]", lo que podría provocar la e... • https://fluidattacks.com/advisories/bts • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •