CNNVD-202511-2360 Information
CNNVD ID
CNNVD-202511-2360
Related CVE
- CNNVD Published: 2025-11-20
Description (Chinese)
Public Knowledge Project Platform OJS/OMP/OPS(PKP Platform OJS/OMP/OPS)是Public Knowledge Project公司的一个开源出版平台。 Public Knowledge Project Platform OJS/OMP/OPS存在代码注入漏洞,该漏洞源于对文件plugins/paymethod/manual/templates/paymentForm.tpl中参数manualInstructions的错误操作,可能导致跨站脚本攻击。
Description (English)
Public Knowledge Project Platform OJS/OMP/OPS (PKP Platform OJS/OMP/OPS) is an open-source publishing platform for Public Knowledge Project. Public Knowledge Project Platform OJS/OMP/OPS contains a code-in-code loophole, which results from an error in the performance of the parameters in document plugins/paymethod/manual/templates/paymentForm.tpl, which may result in a cross-site script attack.
Hazard Level
Critical
Vulnerability Type
代码注入
Affected Vendor
Public Knowledge Project
Published
2025-11-20
Last Modified
2026-02-24
References
https://github.com/pkp/pkp-lib/issues/12022#event-20904087480 https://vuldb.com/?id.333042 https://vuldb.com/?ctiid.333042 https://github.com/pkp/pkp-lib/issues/12022#event-20904112770 https://vuldb.com/?submit.695020 https://access.redhat.com/security/cve/cve-2025-13469
Share on: