Loading HuntDB...

Vulnerabilities

CVE-2024-46326

MEDIUM

Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.

Published Oct 21, 2024

CVE-2024-7902

UNKNOWN

A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Published Aug 17, 2024

CVE-2024-24511

UNKNOWN

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title component.

Published Mar 01, 2024

CVE-2024-25438

UNKNOWN

A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Input subject field under the Add Discussion function.

Published Mar 01, 2024

CVE-2024-24512

UNKNOWN

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.

Published Mar 01, 2024

CVE-2023-5904

LOW

Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5903

LOW

Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5900

LOW

Cross-Site Request Forgery in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5901

LOW

Cross-site Scripting in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5897

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.

Published Nov 01, 2023

CVE-2023-5898

LOW

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5902

MEDIUM

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5896

LOW

Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.4.0-4.

Published Nov 01, 2023

CVE-2023-5899

LOW

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5895

LOW

Cross-site Scripting (XSS) - DOM in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5894

LOW

Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5889

MEDIUM

Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5891

MEDIUM

Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5892

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5893

LOW

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5890

MEDIUM

Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Nov 01, 2023

CVE-2023-5626

LOW

Cross-Site Request Forgery (CSRF) in GitHub repository pkp/ojs prior to 3.3.0-16.

Published Oct 17, 2023

CVE-2023-4695

CRITICAL

Use of Predictable Algorithm in Random Number Generator in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

Published Sep 01, 2023