5.3
CVSSv3

CVE-2023-47271

Published: 06/11/2023 Updated: 20/12/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

PKP-WAL (aka PKP Web Application Library or pkp-lib) prior to 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sfu pkp web application library

Exploits

PKP Web Application Library (PKP-WAL) versions 340-3 and below, as used in Open Journal Systems (OJS), Open Monograph Press (OMP), and Open Preprint Systems (OPS) before versions 340-4 or 330-16, suffer from a NativeImportExportPlugin related remote code execution vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [KIS-2023-14] PKP-WAL &lt;= 340-3 (NativeImportExportPlugin) Remote Code Execution Vulnerability <!--X-Subject-Heade ...