CVE-2024-56525 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as…
Critical CVSS: 9.8

CVE-2024-56525

In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
Vendor
-
Product
-
CWE
CWE-276
Yayın Tarihi
2025-02-24 23:15:10
Güncelleme
2025-02-25 15:15:22
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar