4.3
CVSSv2

CVE-2012-1469

Published: 06/09/2012 Updated: 12/01/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 440
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems prior to 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio Statement or (5) Abstract of Submission fields to the stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.

Vulnerable Product Search on Vulmon Subscribe to Product

pkp open journal systems

Exploits

Open Journal Systems version 236 suffers from file manipulation, cross site scripting, and shell upload vulnerabilities ...
source: wwwsecurityfocuscom/bid/52666/info Open Journal Systems is prone to following multiple vulnerabilities because the software fails to sufficiently sanitize user-supplied input: 1 An arbitrary-file-deletion vulnerability 2 A security vulnerability 3 An arbitrary-file-upload vulnerability 4 Multiple cross-site scripting vuln ...
source: wwwsecurityfocuscom/bid/52666/info Open Journal Systems is prone to following multiple vulnerabilities because the software fails to sufficiently sanitize user-supplied input: 1 An arbitrary-file-deletion vulnerability 2 A security vulnerability 3 An arbitrary-file-upload vulnerability 4 Multiple cross-site scripting vulner ...