File Upload Vulnerability in Open Journal Systems by PKP
CVE-2012-1468

Currently unrated

Key Information:

Vendor

Pkp

Vendor
CVE Published:
6 September 2012

What is CVE-2012-1468?

An incomplete blacklist vulnerability exists in Open Journal Systems affecting versions prior to 2.3.7, where authenticated users with Author Role permissions can exploit the system. This vulnerability permits users to upload files with executable extensions other than '.php', enabling them to execute arbitrary code. Accessing the uploaded files through a direct request poses significant security risks, as demonstrated by the ability to use extensions like .pHp and .asp. Institutions using Open Journal Systems should implement urgent updates and rigorous security measures to mitigate this threat.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.