CVE-2026-6428
5.6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/AU:Y/V:C/U:Amber
Summary
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | 0 <= 22.11.38 | affected |
| Koha Community | Koha | 23.05.00 <= 23.11.15 | affected |
| Koha Community | Koha | 24.05.00 <= 24.11.16 | affected |
| Koha Community | Koha | 25.05.00 <= 25.05.11 | affected |
| Koha Community | Koha | 25.11.00 <= 25.11.05 | affected |
| Koha Community | Koha | 26.05.00 <= 26.05.01 | affected |
Weaknesses
- CWE-89: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
References
- https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42361
- https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=199539
- https://koha-community.org/security-releases/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.