peter bassill · operator
$ cve CVE-2012-1469 JSON

CVE-2012-1469 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio Statement or (5) Abstract of Submission fields to the stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS3.08% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2012-09-06
Last modified2026-06-16

Affected (1)

VendorProduct
pkpopen journal systems

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD