Description
A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22765 | A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function. |
References
History
Fri, 28 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sfu
Sfu open Journal Systems |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:sfu:open_journal_systems:3.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Sfu
Sfu open Journal Systems |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-28T18:51:31.344Z
Reserved: 2024-02-07T00:00:00.000Z
Link: CVE-2024-25436
Updated: 2024-08-01T23:44:09.162Z
Status : Modified
Published: 2024-03-01T23:15:08.410
Modified: 2025-03-28T19:15:19.637
Link: CVE-2024-25436
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD