Metrics
Affected Vendors & Products
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Public Knowledge Project
Public Knowledge Project open Journal Systems Public Knowledge Project open Monograph Press |
|
| Vendors & Products |
Public Knowledge Project
Public Knowledge Project open Journal Systems Public Knowledge Project open Monograph Press |
Thu, 20 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Nov 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross site scripting. The attack can be initiated remotely. You should upgrade the affected component. | |
| Title | Public Knowledge Project omp/ojs Payment Instructions Setting paymentForm.tpl cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-20T13:32:10.915Z
Updated: 2025-11-20T21:00:03.081Z
Reserved: 2025-11-20T07:04:14.906Z
Link: CVE-2025-13469
Updated: 2025-11-20T20:59:56.301Z
Status : Awaiting Analysis
Published: 2025-11-20T15:17:26.853
Modified: 2025-11-21T15:13:59.083
Link: CVE-2025-13469
No data.