CVE-2023-43712
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "access_levels_name" parameter, potentially leading to unauthorized execution of scripts within a user’s web browser.
Date published : 2023-09-30
https://fluidattacks.com/advisories/bts/
https://www.oscommerce.com/