CVE-2026-70370

Summary

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation.

Affected Software

VendorProductVersion RangeStatus
Koha CommunityKoha0 <= 24.11.17affected
Koha CommunityKoha25.05.00 <= 25.05.12affected
Koha CommunityKoha25.11.00 <= 25.11.06affected
Koha CommunityKoha26.05.00 <= 26.05.01affected

Weaknesses

  • CWE-89: CWE-89 SQL Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References