CVE-2022-24181
MEDIUMNuclei
PKP Open Journals System 3.3 - Cross-Site Scripting (XSS)
Record summary
CVE-2022-24181 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBPKP Open Journals System 3.3 - Cross-Site Scripting (XSS)ExploitDB exploitby Hemant KashyapNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMPKP Open Journal Systems 2.4.8-3.3 - Cross-Site ScriptingCVSS 6.1
PKP Open Journal Systems 2.4.8 to 3.3 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary code via the X-Forwarded-Host Header.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.
Remediation
Upgrade to a patched version of PKP Open Journal Systems (OJS) or apply the necessary security patches provided by the vendor.
WeaknessesCWE-79
Authorslucasljm2001, ekrause
Template tagscvecve2022xssosspkp-libedbpublic_knowledge_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:public_knowledge_project:open_journal_systems:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:public_knowledge_project:open_journal_systems"
https://www.exploit-db.com/exploits/50881 https://github.com/pkp/pkp-lib/issues/7649 https://youtu.be/v8-9evO2oVg https://nvd.nist.gov/vuln/detail/cve-2022-24181 https://github.com/comrade99/CVE-2022-24181
Source: ProjectDiscovery
References
2github.com
https://github.com/pkp/pkp-lib/issues/7649 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-24181