Koha Community Koha是Koha Community社区的一款图书馆管理系统。 Koha Community Koha 24.11.17及之前版本、25.05.12及之前版本、25.11.06及之前版本和26.05.01及之前版本存在SQL注入漏洞,该漏洞源于acqui/parcels.pl文件中orderby参数未经过验证直接拼接至SQL ORDER BY子句,可能导致经过身份验证的员工读取任意数据库内容,包括读者个人信息、员工bcrypt密码哈希和双因素密钥。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Koha Community | Koha | < 24.11.18 |
affected |
25.05.0< 25.05.13 |
affected | ||
25.11.0< 25.11.07 |
affected | ||
26.05.0< 26.05.02 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Koha Community | Koha | 0 ~ 24.11.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72607 | 7.1 HIGH | Koha Community Koha - Stored SQL Injection via agefield in Automatic Item Modifications by |
| CVE-2026-72608 | 6.5 MEDIUM | Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name |
| CVE-2026-72610 | 4.3 MEDIUM | Koha Community Koha - Stored SQL Injection via Patron lang Field in Issue Slip Generation |
No comments yet