CVE-2025-13469

Source
https://cve.org/CVERecord?id=CVE-2025-13469
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13469.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13469
Published
2025-11-20T13:32:10.915Z
Modified
2026-07-15T01:49:02.006004802Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
Public Knowledge Project omp/ojs Payment Instructions Setting paymentForm.tpl cross site scripting
Details

A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross site scripting. The attack can be initiated remotely. You should upgrade the affected component.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/13xxx/CVE-2025-13469.json",
    "cwe_ids": [
        "CWE-79",
        "CWE-94"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/pkp/pkp-lib

Affected ranges

Type
GIT
Repo
https://github.com/pkp/pkp-lib
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "3.3.0"
        },
        {
            "last_affected": "3.3.0"
        },
        {
            "introduced": "3.4.0"
        },
        {
            "last_affected": "3.4.0"
        },
        {
            "introduced": "3.5.0"
        },
        {
            "last_affected": "3.5.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

3.*
3.3.0
3.4.0
3.5.0
Other
3_3_0-0
3_3_0-1
3_4_0-0
3_4_0rc1
3_4_0rc2
3_4_0rc3
3_5_0-0
3_5_0rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13469.json"