CVE-2023-47271 describes an improper input validation vulnerability in PKP-WAL (PKP Web Application Library) versions prior to 3.3.0-16, impacting products like Open Journal Systems (OJS). The flaw allows an attacker to upload non-image files through the native import/export plugin, which are then processed as image files. Rated as Medium severity (CVSS 5.3), this vulnerability has a low attack complexity and requires no user interaction, potentially leading to information disclosure (I:L). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion, with mentions of potential Remote Code Execution (RCE) in online forums.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.0-16CPE matchmatch criteria | cpe:2.3:a:sfu:pkp_web_application_library:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.