Vulnerability Description
A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross site scripting. The attack can be initiated remotely. You should upgrade the affected component.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/pkp/pkp-lib/issues/12022
- https://github.com/pkp/pkp-lib/issues/12022#event-20904087480
- https://github.com/pkp/pkp-lib/issues/12022#event-20904112770
- https://vuldb.com/?ctiid.333042
- https://vuldb.com/?id.333042
- https://vuldb.com/?submit.695020
FAQ
What is CVE-2025-13469?
CVE-2025-13469 is a vulnerability with a CVSS score of 2.4 (LOW). A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of ...
How severe is CVE-2025-13469?
CVE-2025-13469 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13469?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.