← Zurück zur CVE-Suche

CVE-2026-70370

Beschreibung

Koha-s reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation.

CVSS 8.8EPSS 0.306%Risiko 0.9
Quelle öffnen
Veröffentlicht
2026-08-04 13:18:57
Zuletzt geändert
2026-08-10 12:17:22
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H