Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-04-01T11:42:09

Updated: 2024-08-03T04:07:01.505Z

Reserved: 2022-01-31T00:00:00

Link: CVE-2022-24181

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-04-01T12:15:07.853

Modified: 2022-04-08T17:43:25.873

Link: CVE-2022-24181

cve-icon Redhat

No data.