CVE-2026-70370
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | 0 <= 24.11.17 | affected |
| Koha Community | Koha | 25.05.00 <= 25.05.12 | affected |
| Koha Community | Koha | 25.11.00 <= 25.11.06 | affected |
| Koha Community | Koha | 26.05.00 <= 26.05.01 | affected |
Weaknesses
- CWE-89: CWE-89 SQL Injection
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42363
- https://koha-community.org/koha-25-05-12-released/
- https://download.koha-community.org/koha-25.05.12.tar.gz
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.