Koha是Koha社区开源的一个用于图书馆自动化管理建站系统。 Koha 26.05.01-1及之前版本存在SQL注入漏洞,该漏洞源于reports/guided_reports.pl中的guided report builder读取order_by CGI参数和动态的{order}_ovalue参数,并将其直接拼接到SQL ORDER BY子句,缺乏白名单或验证,可能导致低权限员工账户通过时间盲注攻击获取数据库中的读者个人信息及员工/LDAP凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | ≤ 26.05.01-1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Koha Community | Koha | 0 ~ 26.05.01-1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet