PKP Open Journal Systems 2.4.8 to 3.3 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary code via the X-Forwarded-Host Header.
id: CVE-2022-24181
info:
name: PKP Open Journal Systems 2.4.8-3.3 - Cross-Site Scripting
author
...