CVE-2015-4631
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
7Exploited in Wild
-Decision
Descriptions
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-search.pl; the (2) value parameter to authorities/authorities-home.pl; the (3) delay parameter to acqui/lateorders.pl; the (4) authtypecode or (5) tagfield to admin/auth_subfields_structure.pl; the (6) tagfield parameter to admin/marc_subfields_structure.pl; the (7) limit parameter to catalogue/search.pl; the (8) bookseller_filter, (9) callnumber_filter, (10) EAN_filter, (11) ISSN_filter, (12) publisher_filter, or (13) title_filter parameter to serials/serials-search.pl; or the (14) author, (15) collectiontitle, (16) copyrightdate, (17) isbn, (18) manageddate_from, (19) manageddate_to, (20) publishercode, (21) suggesteddate_from, or (22) suggesteddate_to parameter to suggestion/suggestion.pl; or the (23) direction, (24) display or (25) addshelf parameter to opac-shelves.pl.
Múltiples vulnerabilidades Cross-Site Scripting (XSS) en Koha, en versiones 3.14.x anteriores a la 3.14.16, versiones 3.16.x anteriores a la 3.16.12, versiones 3.18.x anteriores a la 3.18.08 y versiones 3.20.x anteriores a la 3.20.1, permiten que atacantes remotos inyecten scripts web o HTML arbitrarios mediante (1) el parámetro tag en opac-search.pl; (2) el parámetro value en authorities/authorities-home.pl; (3) el parámetro delay en acqui/lateorders.pl; (4) los parámetros authtypecode o (5) tagfield en admin/auth_subfields_structure.pl; (6) el parámetro tagfield en admin/marc_subfields_structure.pl; (7) el parámetro limit en catalogue/search.pl; (8) los parámetros bookseller_filter, (9) callnumber_filter, (10) EAN_filter, (11) ISSN_filter, (12) publisher_filter o (13) title_filter en serials/serials-search.pl; o (14) los parámetros author, (15) collectiontitle, (16) copyrightdate, (17) isbn, (18) manageddate_from, (19) manageddate_to, (20) publishercode, (21) suggesteddate_from o (22) suggesteddate_to en suggestion/suggestion.pl o los parámetros (23) direction, (24) display o (25) addshelf en opac-shelves.pl.
Koha ILS suffers from cross site request forgery, cross site scripting, remote SQL injection, and path traversal vulnerabilities. Versions 3.20.x less than or equal to 3.20.1, 3.18.x less than or equal to 3.18.8, and 3.16.x less than or equal to 3.16.12 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-16 CVE Reserved
- 2015-06-26 CVE Published
- 2015-06-26 First Exploit
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (12)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://koha-community.org/koha-3-14-16-released | 2018-12-04 | |
https://koha-community.org/security-release-koha-3-16-12 | 2018-12-04 | |
https://koha-community.org/security-release-koha-3-18-8 | 2018-12-04 | |
https://koha-community.org/security-release-koha-3-20-1 | 2018-12-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.14.00 < 3.14.16 Search vendor "Koha" for product "Koha" and version " >= 3.14.00 < 3.14.16" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.16.00 < 3.16.12 Search vendor "Koha" for product "Koha" and version " >= 3.16.00 < 3.16.12" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.18.0 < 3.18.8 Search vendor "Koha" for product "Koha" and version " >= 3.18.0 < 3.18.8" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.20.00 < 3.20.1 Search vendor "Koha" for product "Koha" and version " >= 3.20.00 < 3.20.1" | - |
Affected
|