PT-2025-47575 · Public Knowledge · Ojs+1

·

CVE-2025-13469

·

Published

2025-11-20

·

Updated

2025-11-20

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions Public Knowledge Project omp and ojs versions 3.3.0 through 3.5.0
Description A security issue exists in Public Knowledge Project omp and ojs. The manipulation of the manualInstructions argument in an unknown function within the file plugins/paymethod/manual/templates/paymentForm.tpl of the Payment Instructions Setting Handler component can lead to cross site scripting. This attack can be initiated remotely.
Recommendations Upgrade the affected component to address this issue.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13469

Affected Products

Ojs
Omp