Record summary

CVE-2022-24181 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBPKP Open Journals System 3.3 - Cross-Site Scripting (XSS)ExploitDB exploitby Hemant KashyapNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMPKP Open Journal Systems 2.4.8-3.3 - Cross-Site ScriptingCVSS 6.1

PKP Open Journal Systems 2.4.8 to 3.3 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary code via the X-Forwarded-Host Header.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.

Remediation

Upgrade to a patched version of PKP Open Journal Systems (OJS) or apply the necessary security patches provided by the vendor.

WeaknessesCWE-79
Authorslucasljm2001, ekrause
Template tagscvecve2022xssosspkp-libedbpublic_knowledge_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:public_knowledge_project:open_journal_systems:*:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:public_knowledge_project:open_journal_systems"

Source: ProjectDiscovery

References

2