Replies: 1 comment
-
@kokart, please see https://github.com/pkp/ojs/blob/main/SECURITY.md for details on responsible disclosure of potential security issues. The If you're willing to replicate these issues and provide details, then they could be valuable; raw reports out of SAST tools typically produce a lot of false positives and are very time-consuming to work with. Especially in Spanish, which is not my strongest language! |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
After a SAST execution we have detected differents issues.
These are critical:
SQL_INJECTION.pdf
INJECTION JSON.pdf
CROSS-SITING DOM.pdf
I've attached the related report in Spanish , but the full report shows more issues:

Thank you
Beta Was this translation helpful? Give feedback.
All reactions