CNNVD-202511-2360 Information

CNNVD ID

CNNVD-202511-2360

CVE-2025-13469

  • CNNVD Published: 2025-11-20

Description (Chinese)

Public Knowledge Project Platform OJS/OMP/OPS(PKP Platform OJS/OMP/OPS)是Public Knowledge Project公司的一个开源出版平台。 Public Knowledge Project Platform OJS/OMP/OPS存在代码注入漏洞,该漏洞源于对文件plugins/paymethod/manual/templates/paymentForm.tpl中参数manualInstructions的错误操作,可能导致跨站脚本攻击。

Description (English)

Public Knowledge Project Platform OJS/OMP/OPS (PKP Platform OJS/OMP/OPS) is an open-source publishing platform for Public Knowledge Project. Public Knowledge Project Platform OJS/OMP/OPS contains a code-in-code loophole, which results from an error in the performance of the parameters in document plugins/paymethod/manual/templates/paymentForm.tpl, which may result in a cross-site script attack.

Hazard Level

Critical

Vulnerability Type

代码注入

Affected Vendor

Public Knowledge Project

Published

2025-11-20

Last Modified

2026-02-24

References

https://github.com/pkp/pkp-lib/issues/12022#event-20904087480 https://vuldb.com/?id.333042 https://vuldb.com/?ctiid.333042 https://github.com/pkp/pkp-lib/issues/12022#event-20904112770 https://vuldb.com/?submit.695020 https://access.redhat.com/security/cve/cve-2025-13469

Share on: