CVE-2026-70372
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized by a table-name prefix and is never whitelisted, landing verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY); Filter values are concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments, and the Limit parameter is appended raw to a LIMIT clause. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | 0 < 24.11.17 | affected |
| Koha Community | Koha | 25.05.00 < 25.05.12 | affected |
| Koha Community | Koha | 25.11.00 < 25.11.06 | affected |
| Koha Community | Koha | 26.05.00 < 26.05.01 | affected |
Weaknesses
- CWE-89: CWE-89 SQL Injection
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42369
- https://koha-community.org/koha-25-05-12-released/
- https://download.koha-community.org/koha-25.05.12.tar.gz
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.