Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2025-22954 โ€” AI Deep Analysis Summary

CVSS 10.0 ยท Critical

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: Critical SQL Injection in Koha library management system. ๐Ÿ’ฅ **Consequences**: Full database compromise, data theft, system takeover. CVSS Score: 10.0 (Critical).

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: CWE-89 (SQL Injection). ๐Ÿ› **Flaw**: The `supplierid` parameter in `GetLateOrMissingIssues` is not sanitized. Malicious input executes arbitrary SQL commands.

Q3Who is affected? (Versions/Components)

๐Ÿข **Affected**: Koha Library Automation System. ๐Ÿ“… **Versions**: 21.11 and earlier. โš ๏ธ **Status**: Vulnerable until patch 24.11.02.

Q4What can hackers do? (Privileges/Data)

๐Ÿ•ต๏ธ **Hacker Actions**: Read/Modify/Delete DB data. ๐Ÿ—„๏ธ **Impact**: Access to patron records, financial data, and system configurations. Full control over the library's digital infrastructure.

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: LOW. ๐ŸŒ **Access**: Network Accessible (AV:N). ๐Ÿ”‘ **Auth**: None required (PR:N). ๐Ÿ–ฑ๏ธ **UI**: None required (UI:N). Easy to exploit remotely.

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ’ฃ **Exploit**: YES. ๐Ÿ“‚ **PoC**: Available on GitHub (RandomRobbieBF/CVE-2025-22954). ๐ŸŽฏ **Target**: `/serials/lateissues-export.pl` via `supplierid` or `serialid` params.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Check**: Scan for Koha instances. ๐Ÿ“ **Endpoint**: Look for `/serials/lateissues-export.pl`. ๐Ÿงช **Test**: Inject SQL payloads into `supplierid` parameter. ๐Ÿ“Š **Scan**: Use tools detecting CWE-89 in Koha contexts.

Q8Is it fixed officially? (Patch/Mitigation)

๐Ÿ› ๏ธ **Fix**: Upgrade to Koha version **24.11.02** or later. ๐Ÿ“œ **Reference**: See koha-community.org release notes. โœ… **Status**: Patched in latest stable release.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch?**: Block external access to `/serials/lateissues-export.pl`. ๐Ÿ›‘ **WAF**: Deploy Web Application Firewall rules to filter SQL injection patterns in `supplierid`. ๐Ÿ”’ **Isolate**: Limit network exposure.

Q10Is it urgent? (Priority Suggestion)

๐Ÿ”ฅ **Urgency**: CRITICAL. ๐Ÿš€ **Priority**: Patch IMMEDIATELY. ๐Ÿ“‰ **Risk**: CVSS 10.0 + Public PoC. โณ **Time**: Exploitation is easy and widespread potential.