Cross-Site Scripting Vulnerabilities in Open Journal Systems by PKP
CVE-2012-1469
Currently unrated
What is CVE-2012-1469?
Multiple cross-site scripting (XSS) vulnerabilities exist in Open Journal Systems versions before 2.3.7. These vulnerabilities allow remote attackers and authenticated users to inject arbitrary web scripts or HTML through various parameters in the iBrowser plugin and other functions. Specific entry points include the editor, callback parameters within the iBrowser plugin, authors' URL parameters, and submission fields such as Bio Statement and Abstract. Exploitation of these vulnerabilities could lead to unauthorized disclosure of information or other malicious actions.
