ZeroHour

CVE-2019-19909

CVSS 3.1
8.8 high
EPSS
1%p71
Published
()
Modified
Description

An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.

Vendors
sfu
Products
open journal system
Weakness
CWE-94, CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.