ZeroHour

CVE-2024-24512

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p43
Published
()
Modified
Description

Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle component.

Vendors
pkp.sfu
Products
open journal systems
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.