Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other products, does not verify that the file named in an XML document (used for the native import/export plugin) is an image file, before trying to use it for an issue cover image.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PKP Web Application Library 安全漏洞
Vulnerability Description
PKP Web Application Library是PKP公司的开放期刊系统 (OJS)、开放会议系统 (OCS)、开放专着出版社 (OMP)、开放预印本系统 (OPS) 和开放收割机系统 (OHS) 共享的库。 PKP Web Application Library(PKP-WAL)3.3.0-16 之前版本存在安全漏洞,该漏洞源于不会验证 XML 文档中指定的文件是否为图像文件,然后将其用于问题封面图像。
CVSS Information
N/A
Vulnerability Type
N/A