Os Commerce 4.12.56860 - Cross Site Scripting Reflected (XSS)
Description
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "countries_name[1]" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Os Commerce is susceptible to a stored XSS vulnerability via the 'countries_name[1]' parameter, allowing attackers to inject malicious scripts.
Vulnerability
Os Commerce is susceptible to a stored Cross-Site Scripting (XSS) vulnerability through the countries_name[1] parameter. This allows attackers to inject malicious JavaScript code that is stored and executed when other users access the affected page. The vulnerability exists in versions prior to the fix, as disclosed on the Fluid Attacks advisory [2].
Exploitation
An attacker with access to the admin panel can inject a malicious payload into the countries_name[1] parameter. The payload is then stored and executed in the browser of any user viewing the affected page. No authentication is required beyond admin privileges to trigger the injection, but the stored script affects all users including administrators.
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information. The impact is limited to the admin panel's context.
Mitigation
Update to the latest version of Os Commerce as provided by the vendor. As of the publication date, no specific patch version is mentioned in the available references. Refer to the official website [1] for updates. No workarounds are documented.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Os Commerce/Os Commercev5Range: 4.12.56860
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.