Логотип exploitDog
bind:CVE-2023-47271
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-47271

Количество 2

Количество 2

nvd логотип

CVE-2023-47271

больше 2 лет назад

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8f7j-g5xp-rc4p

больше 2 лет назад

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-47271

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-8f7j-g5xp-rc4p

PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу