Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4265 | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin. |
Tue, 25 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-276 | |
| Metrics |
cvssV3_1
|
Mon, 24 Feb 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-25T14:26:32.690Z
Reserved: 2024-12-27T00:00:00.000Z
Link: CVE-2024-56525
Updated: 2025-02-25T14:26:26.272Z
Status : Deferred
Published: 2025-02-24T23:15:10.793
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-56525
No data.
OpenCVE Enrichment
No data.
EUVD