// For flags

CVE-2015-4631

Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities

Severity Score

5.4
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

7
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-search.pl; the (2) value parameter to authorities/authorities-home.pl; the (3) delay parameter to acqui/lateorders.pl; the (4) authtypecode or (5) tagfield to admin/auth_subfields_structure.pl; the (6) tagfield parameter to admin/marc_subfields_structure.pl; the (7) limit parameter to catalogue/search.pl; the (8) bookseller_filter, (9) callnumber_filter, (10) EAN_filter, (11) ISSN_filter, (12) publisher_filter, or (13) title_filter parameter to serials/serials-search.pl; or the (14) author, (15) collectiontitle, (16) copyrightdate, (17) isbn, (18) manageddate_from, (19) manageddate_to, (20) publishercode, (21) suggesteddate_from, or (22) suggesteddate_to parameter to suggestion/suggestion.pl; or the (23) direction, (24) display or (25) addshelf parameter to opac-shelves.pl.

Múltiples vulnerabilidades Cross-Site Scripting (XSS) en Koha, en versiones 3.14.x anteriores a la 3.14.16, versiones 3.16.x anteriores a la 3.16.12, versiones 3.18.x anteriores a la 3.18.08 y versiones 3.20.x anteriores a la 3.20.1, permiten que atacantes remotos inyecten scripts web o HTML arbitrarios mediante (1) el parámetro tag en opac-search.pl; (2) el parámetro value en authorities/authorities-home.pl; (3) el parámetro delay en acqui/lateorders.pl; (4) los parámetros authtypecode o (5) tagfield en admin/auth_subfields_structure.pl; (6) el parámetro tagfield en admin/marc_subfields_structure.pl; (7) el parámetro limit en catalogue/search.pl; (8) los parámetros bookseller_filter, (9) callnumber_filter, (10) EAN_filter, (11) ISSN_filter, (12) publisher_filter o (13) title_filter en serials/serials-search.pl; o (14) los parámetros author, (15) collectiontitle, (16) copyrightdate, (17) isbn, (18) manageddate_from, (19) manageddate_to, (20) publishercode, (21) suggesteddate_from o (22) suggesteddate_to en suggestion/suggestion.pl o los parámetros (23) direction, (24) display o (25) addshelf en opac-shelves.pl.

Koha ILS suffers from cross site request forgery, cross site scripting, remote SQL injection, and path traversal vulnerabilities. Versions 3.20.x less than or equal to 3.20.1, 3.18.x less than or equal to 3.18.8, and 3.16.x less than or equal to 3.16.12 are affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-06-16 CVE Reserved
  • 2015-06-26 CVE Published
  • 2015-06-26 First Exploit
  • 2024-08-06 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Koha
Search vendor "Koha"
Koha
Search vendor "Koha" for product "Koha"
>= 3.14.00 < 3.14.16
Search vendor "Koha" for product "Koha" and version " >= 3.14.00 < 3.14.16"
-
Affected
Koha
Search vendor "Koha"
Koha
Search vendor "Koha" for product "Koha"
>= 3.16.00 < 3.16.12
Search vendor "Koha" for product "Koha" and version " >= 3.16.00 < 3.16.12"
-
Affected
Koha
Search vendor "Koha"
Koha
Search vendor "Koha" for product "Koha"
>= 3.18.0 < 3.18.8
Search vendor "Koha" for product "Koha" and version " >= 3.18.0 < 3.18.8"
-
Affected
Koha
Search vendor "Koha"
Koha
Search vendor "Koha" for product "Koha"
>= 3.20.00 < 3.20.1
Search vendor "Koha" for product "Koha" and version " >= 3.20.00 < 3.20.1"
-
Affected