PKP Open Journal Systems 2.4.8 to 3.3 contains a cross-site scripting vulnerability which allows remote attackers to inject arbitrary code via the X-Forwarded-Host Header.
View the template here CVE-2022-24181.yaml
References:
https://nvd.nist.gov/vuln/detail/cve-2022-24181