CVE-2024-56525 Information
Feb 26, 2025
cve
Description
In Public Knowledge Project (PKP) OJS OMP and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8 an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context and insert a backdoor plugin by uploading a crafted XML document as a User XML Plugin.
Reference
https://openjournaltheme.com/user-xml-fatal-vulnerabilities-for-ojs-omp-ops-3-3-0-21-cve-2024-56525/
Share on: