Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Srivishnu P

#20781of 53,632
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2024-20430
6.1
2024-03-01
Public Knowledge · Pkp Ojs · CVE-2024-24511
**Name of the Vulnerable Software and Affected Versions** PKP OJS version 3.4 **Description** The issue allows an attacker to execute arbitrary code via the Input Title component. This is a Cross Site Scripting vulnerability. **Recommendations** For PKP OJS version 3.4, consider disabling the Input Title component until a patch is available to prevent exploitation. Restrict access to this component to minimize the risk of arbitrary code execution. Avoid using the Input Title component in sensitive areas of the application until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2024-20431
6.1
2024-03-01
Public Knowledge · Pkp Ojs · CVE-2024-24512
**Name of the Vulnerable Software and Affected Versions** Pkp OJS version 3.4 **Description** The issue allows an attacker to execute arbitrary code via the input subtitle component. This is a Cross Site Scripting vulnerability. **Recommendations** For Pkp OJS version 3.4, consider disabling the input subtitle component until a patch is available to prevent exploitation. Restrict access to this component to minimize the risk of arbitrary code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.