VYPR

Open Journal Systems

by Public Knowledge Project

CVEs (6)

  • CVE-2019-19909HigDec 19, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.

  • CVE-2022-24181MedApr 1, 2022
    risk 0.43cvss 6.1epss 0.06

    Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

  • CVE-2024-25438MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.

  • CVE-2022-26616MedApr 4, 2022
    risk 0.40cvss 6.1epss 0.01

    PKP Vendor Open Journal System v2.4.8 to v3.3.8 allows attackers to perform reflected cross-site scripting (XSS) attacks via crafted HTTP headers.

  • CVE-2024-7902MedAug 17, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be…

  • CVE-2011-5196Sep 23, 2012
    risk 0.03cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in index/manager/fileUpload in Public Knowledge Project Open Journal Systems 2.3.6 and earlier allows remote attackers to hijack the authentication of administrators for requests that upload PHP files.