Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8f7j-g5xp-rc4p

Опубликовано: 06 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

EPSS

Процентиль: 36%
0.00155
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 2 лет назад

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

EPSS

Процентиль: 36%
0.00155
Низкий

5.3 Medium

CVSS3