Koha Community Koha是Koha Community社区的一款图书馆管理系统。 Koha Community Koha 24.11.17及之前版本、25.05.12及之前版本、25.11.06及之前版本和26.05.01及之前版本存在SQL注入漏洞,该漏洞源于自动条目修改规则的agefield值存储了SQL有效载荷,且未参数化插入SQL查询,可能导致具有tools => items_batchmod权限的经过身份验证的员工读取任意数据库内容,包括用户个人隐私信息和密码哈希。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | < 24.11.18 |
affected |
25.05.0< 25.05.13 |
affected | ||
25.11.0< 25.11.07 |
affected | ||
26.05.0< 26.05.02 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Koha Community | Koha | 0 ~ 24.11.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72609 | 7.1 HIGH | Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl |
| CVE-2026-72608 | 6.5 MEDIUM | Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name |
| CVE-2026-72610 | 4.3 MEDIUM | Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation |
No comments yet