Published 2026-09-16
license
Article

Comparative Vulnerability Analysis of Open-Source Editorial Management Systems: OJS and DSpace Under Adversarial Evaluation

DOI: https://doi.org/10.22490/25394088.11793
Jorge Eliecer Hernandez Pérez Universidad Nacional Abierta y a Distancia image/svg+xml

This study evaluates and compares the security posture of Open Journal Systems (OJS) 3.3.0.20 and DSpace 7.6.7 through systematic review of the National Vulnerability Database and ethical penetration testing in isolated laboratory environments. Five CVEs were identified in OJS, most of them involving Cross-Site Scripting or Cross-Site Request Forgery; DSpace showed two registered vulnerabilities, including a Directory Traversal rated CVSS 7.2.

Technical evaluation proceeded in four phases: passive reconnaissance, automated scanning with OWASP ZAP, manual verification with Burp Suite, and comparative analysis. The central finding is confirmed, exploitable CSRF vulnerability in OJS specifically, the server accepted authentication requests without checking the synchronization token and issued valid sessions (CVE-2023-6671, CVSS 8.8). In DSpace, what OWASP ZAP classified as a High-level SQL Injection turned out to be improper error handling once tested manually. Neither platform used TLS encryption or Content Security Policy headers.

OJS showed a medium-high risk profile. DSpace showed a medium one, complicated by a security gap between its Angular frontend and its REST API backend. The deficiencies found in both platforms say less about the software than about how institutions in Latin America tend to deploy and maintain it. This study derives technical and institutional mitigation guidelines from those findings.

keywords: cybersecurity, ethical penetration testing, Open Journal Systems, DSpace, CSRF, vulnerability analysis, adversarial thinking, academic editorial security
license

How to Cite

Hernandez Pérez, J. E. (2026). Comparative Vulnerability Analysis of Open-Source Editorial Management Systems: OJS and DSpace Under Adversarial Evaluation. Publicaciones E Investigación, 20(2). https://doi.org/10.22490/25394088.11793
Almétricas

PRIVACY STATEMENT: In accordance with the Personal Data Protection Law (Law 1581 of 2012), the names and email addresses managed by Publicaciones e Investigación will be used exclusively for the purposes stated by this journal and will not be made available for any other purpose or to any other individual. Manuscripts submitted to the publication are only accessible to the editorial team and external peer reviewers. 

Design and implemented by