CVE-2025-13469
Published
CVSS v3
2.4
LOW
CVSS v2
3.3
LOW
Affected
1
PROJECT
Description
A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unknown function of the file plugins/paymethod/manual/templates/paymentForm.tpl of the component Payment Instructions Setting Handler. The manipulation of the argument manualInstructions leads to cross site scripting. The attack can be initiated remotely. You should upgrade the affected component.
The library used by PKP's applications OJS, OMP and OPS, open source software for scholarly publishing.