← Späť na vyhľadávanie CVE

CVE-2026-6428

Koha

Popis

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.

CVSS 7.6EPSS 0.244%Riziko 0.78
Zobraziť zdroj
Zverejnené
2026-06-13 17:16:17
Dotknuté verzie
<22.11.38, <24.11.16, <25.05.11, <25.11.05, <26.05.01, <26.11.00
Typ
Iné
Posledná úprava
2026-08-10 12:17:22
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L