Vulnerability in PKP OJS Allows Open Redirect Attacks
CVE-2024-7902

6.1MEDIUM

Key Information:

Vendor

Pkp

Status
Vendor
CVE Published:
17 August 2024

What is CVE-2024-7902?

A problematic open redirect vulnerability has been identified in the PKP Open Journal Systems affecting versions up to 3.4.0-6. The issue resides within the /login/signOut functionality, where manipulation of the 'source' argument can redirect users to unverified external domains, such as .example.com. This flaw can be exploited remotely, posing significant security threats to users and potentially allowing attackers to redirect unsuspecting victims to malicious sites. Despite early disclosure efforts to the vendor, there has been no responsive action regarding this security concern. Users of the affected versions are strongly encouraged to implement appropriate safeguards against unauthorized redirects.

Affected Version(s)

ojs 3.4.0-6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KaioGomes (VulDB User)
.