Koha Community Koha是Koha Community社区的一款图书馆管理系统。 Koha Community Koha 24.11.17及之前版本、25.05.12及之前版本、25.11.06及之前版本和26.05.01及之前版本存在SQL注入漏洞,该漏洞源于patron card layout的image_name字段未经验证被原样存储并拼接到SQL查询中,可能导致经过身份验证的攻击者利用tools => label_creator权限执行任意SQL,读取整个Koha数据库中的用户个人信
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | < 24.11.18 |
affected |
25.05.0< 25.05.13 |
affected | ||
25.11.0< 25.11.07 |
affected | ||
26.05.0< 26.05.02 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Koha Community | Koha | 0 ~ 24.11.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72607 | 7.1 HIGH | Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by |
| CVE-2026-72609 | 7.1 HIGH | Koha Community Koha - SQL Injection via ORDER BY Direction in acqui/parcels.pl |
| CVE-2026-72610 | 4.3 MEDIUM | Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation |
No comments yet