Vulnerability Description
Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://drive.google.com/file/d/1AVVw1aibDPBHakU8eTpCA6hna5Ecg2UJ/view
- https://github.com/beraoudabdelkhalek/research/blob/main/CVEs/CVE-2024-46326/REA
- https://github.com/pkp/pkp-lib/issues/10478
FAQ
What is CVE-2024-46326?
CVE-2024-46326 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Public Knowledge Project pkp-lib 3.4.0-7 and earlier is vulnerable to Open redirect due to a lack of input sanitization in the logout function.
How severe is CVE-2024-46326?
CVE-2024-46326 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-46326?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.