CVE-2024-7902

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-7902
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-7902.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-7902
Published
2024-08-17T22:15:04Z
Modified
2024-10-08T04:25:45.300153Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was found in pkp ojs up to 3.4.0-6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login/signOut. The manipulation of the argument source with the input .example.com leads to open redirect. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References

Affected packages

Git / github.com/pkp/ojs

Affected ranges

Type
GIT
Repo
https://github.com/pkp/ojs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

3_2_0-0
3_3_0-0
3_3_0-1
3_4_0-0
3_4_0-1
3_4_0-2
3_4_0-3
3_4_0-4
3_4_0-5
3_4_0-6
3_4_0rc1
3_4_0rc2
3_4_0rc3
ojs-2_0_0-0
ojs-2_0_1-0
ojs-2_0_2-0
ojs-2_0_2-1
ojs-2_1_0-0
ojs-2_1_0-1
ojs-2_1_1-0
ojs-2_1_1rc4
ojs-2_1b
ojs-2_2_0-0
ojs-2_2_0-b1
ojs-2_2_0-b2
ojs-2_2_1-0
ojs-2_2_1-b1
ojs-2_3_0-0
ojs-2_3_0-0rc1
ojs-2_3_1-0
ojs-2_3_1-1
ojs-2_3_1-2
ojs-2_3_3-0
ojs-2_3_3-1
ojs-2_4_0-0
ojs-3_0a1
ojs-3_0b1
ojs2-base-2_2_2