CVE-2024-56525
CVE-2024-56525
Título es
CVE-2024-56525
Lun, 24/02/2025 – 23:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-56525
Descripción en
In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.
25/02/2025
25/02/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
User-XML Fatal Vulnerabilities For OJS/OMP/OPS < 3.3.0.21 (CVE 2024-56525)
Enviar en el boletín
Off
