High severity8.8NVD Advisory· Published Dec 19, 2019· Updated Jun 17, 2026
CVE-2019-19909
CVE-2019-19909
Description
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Public Knowledge Project/pkp-libdescription
- Range: <3.1.2-2
- Range: <3.1.2-2
Patches
Vulnerability mechanics
References
3- github.com/pkp/pkp-lib/compare/3_1_2-1...3_1_2-2nvdPatchThird Party Advisory
- github.com/pkp/pkp-lib/issues/5302nvdThird Party Advisory
- pkp.sfu.ca/ojs/ojs_download/nvdVendor Advisory
News mentions
0No linked articles in our index yet.