In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
History

Tue, 25 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-276
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Feb 2025 23:00:00 +0000

Type Values Removed Values Added
Description In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-25T14:26:32.690Z

Reserved: 2024-12-27T00:00:00.000Z

Link: CVE-2024-56525

cve-icon Vulnrichment

Updated: 2025-02-25T14:26:26.272Z

cve-icon NVD

Status : Received

Published: 2025-02-24T23:15:10.793

Modified: 2025-02-25T15:15:22.190

Link: CVE-2024-56525

cve-icon Redhat

No data.