S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-24181 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in PKP Open Journals System affects v. from 2.4.8 to 3.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-24181
6.1
CVSS

Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

PKP Open Journals System is an open-source software used by academic and research institutions to manage and publish peer-reviewed journals. This platform enables publishers to create journal websites, design journal content, publish articles, and manage submissions. The PKP Open Journals System is a popular and widely used tool in the academic industry, with over 10,000 journals hosted on the platform. It is a critical tool for researchers who want to disseminate their research across the industry.

The CVE-2022-24181 vulnerability is a serious security issue recently detected in the PKP Open Journals System. This vulnerability allows remote attackers to inject arbitrary code via the X-Forwarded-Host header. The vulnerability is most dangerous as it allows attackers to bypass security restrictions, redirect users to malicious websites, and steal sensitive data. The PKP Open Journals System is vulnerable to cross-site scripting (XSS) attacks allowing attackers to execute malicious code on the user's browser. Attackers can easily exploit this vulnerability by injecting code in the host header field.

This vulnerability can significantly affect the academic community, leading to reputational damage, data breaches, and loss of valuable information. Hackers can gain access to user's login data, personal information, and even steal copyrighted material. This can lead to financial losses and lawsuits, affecting the professional reputation of journals and institutions. An attacker can also gain access to the research data of scholars, leading to loss of intellectual property, and subsequent damages.

In conclusion, it is crucial to keep all digital assets as safe and secure as possible. The PKP Open Journals System 2.4.8 through 3.3 vulnerability can lead to significant consequences for academic institutions and publishers. At s4e.io, we provide advanced security solutions to help safeguard digital assets from potential threats. We offer a range of features that will enable you to conduct regular vulnerability scans to identify potential threats and ensure that your digital assets are secure. With our platform, you can rest assured that your digital assets are secure, and you can focus more on what matters most – your research.

 

REFERENCES

Solution Advice

To protect against this vulnerability, publishers can take several precautions to safeguard their journals. The following is a list of measures that can be taken:

  • Install the latest version of the PKP Open Journals System, which has fixed the bug.
  • Implement web application firewalls (WAFs), which can help detect and block suspicious activity.
  • Use security plugins that can help detect, block, and alert on any X-Forwarded-Host header injection.
  • Review the code base and ensure that any user inputs are properly sanitized and validated.
  • Train editors and staff on best security practices and how to detect and report potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.