Koha是Koha组织的一个用于图书馆自动化管理建站系统。 Koha存在安全漏洞,该漏洞源于/cgi-bin/koha/suggestion/suggestion.pl端点中displayby参数验证不当,可能导致低权限工作人员用户通过特制请求注入任意SQL查询,从而完全破坏后端数据库。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | 24.11.0≤ 24.11.12 |
affected |
25.05.0≤ 25.05.07 |
affected | ||
25.11.0≤ 25.11.01 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Koha Community | Koha | 24.11.0 ~ 24.11.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet