---
title: "CVE-2012-1469\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-1469?format=md
keywords: index, follow
---

# CVE-2012-1469

Publication date 6 September 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple cross-site scripting (XSS) vulnerabilities in Open Journal Systems
before 2.3.7 allow remote attackers and remote authenticated users to
inject arbitrary web script or HTML via the (1) editor or (2) callback
parameters to
lib/pkp/lib/tinymce/jscripts/tiny\_mce/plugins/ibrowser/ibrowser.php in the
iBrowser plugin, (3) authors[][url] parameter to index.php, or (4) Bio
Statement or (5) Abstract of Submission fields to the stripUnsafeHtml
function in lib/pkp/classes/core/String.inc.php.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ojs | 13.04 raring | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 11.10 oneiric | Ignored end of life |
| 11.04 natty | Ignored end of life |
| 10.04 LTS lucid | Not in release |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1469)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-1469)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-1469)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-1469)

### Other references

* <https://www.htbridge.com/advisory/HTB23079>
* <http://xforce.iss.net/xforce/xfdb/74227>
* <http://xforce.iss.net/xforce/xfdb/74226>
* <http://xforce.iss.net/xforce/xfdb/74225>
* <http://secunia.com/advisories/48464>
* <http://secunia.com/advisories/48449>
* <http://pkp.sfu.ca/support/forum/viewtopic.php?f=2&t=8431>
* <http://pkp.sfu.ca/ojs/RELEASE-2.3.7>
* <http://archives.neohapsis.com/archives/bugtraq/2012-03/0102.html>
* <https://www.cve.org/CVERecord?id=CVE-2012-1469>
