CVE-2012-1469

N/A Unknown
Published: September 06, 2012 Modified: April 29, 2026
View on NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems before 2.3.7 allow remote attackers and remote authenticated users to inject arbitrary web script or HTML via the (1) editor or (2) callback parameters to lib/pkp/lib/tinymce/jscripts/tiny_mce/plugins/ibrowser/ibrowser.php in the iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio Statement or (5) Abstract of Submission fields to the stripUnsafeHtml function in lib/pkp/classes/core/String.inc.php.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/48449
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/48464
Source: cve@mitre.org
Vendor Advisory
http://www.osvdb.org/80255
Source: cve@mitre.org
http://www.osvdb.org/80256
Source: cve@mitre.org
http://www.osvdb.org/80257
Source: cve@mitre.org
https://www.htbridge.com/advisory/HTB23079
Source: cve@mitre.org
Exploit
http://archives.neohapsis.com/archives/bugtraq/2012-03/0102.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://pkp.sfu.ca/ojs/RELEASE-2.3.7
Source: af854a3a-2127-422b-91ae-364da2661108
http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/48449
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/48464
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.osvdb.org/80255
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/80256
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.osvdb.org/80257
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/74225
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/74226
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/74227
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/74228
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.htbridge.com/advisory/HTB23079
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit

26 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
3.1%
86th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

pkp