CVE-2012-1469

PKP Open Journal Systems < 2.3.6 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio Statement or (5) Abstract of Submission fields to the stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by High-Tech Bridge · textwebappsphp
https://www.exploit-db.com/exploits/37000
exploitdb WRITEUP VERIFIED
by High-Tech Bridge · textwebappsphp
https://www.exploit-db.com/exploits/36999

Scores

EPSS 0.3303
EPSS Percentile 96.8%

Classification

CWE
CWE-79
Status published

Affected Products (2)

pkp/open_journal_systems < 2.3.6
n/a/n/a

Timeline

Published Sep 06, 2012
Tracked Since Feb 18, 2026