CVE-2015-4633
Koha 3.20.1 - Multiple SQL Injections
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
7Exploited in Wild
-Decision
Descriptions
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.
Múltiples vulnerabilidades Cross-Site Scripting (XSS) en Koha, en versiones 3.14.x anteriores a la 3.14.16, versiones 3.16.x anteriores a la 3.16.12, versiones 3.18.x anteriores a la 3.18.08 y versiones 3.20.x anteriores a la 3.20.1, permiten (1) que atacantes remotos ejecuten comandos SQL arbitrarios mediante el parámetro number en opac-tags_subject.pl en la interfaz OPAC o (2) que usuarios autenticados remotos ejecuten comandos SQL arbitrarios mediante los parámetros Filter o (3) Criteria en reports/borrowers_out.pl en la interfaz Staff.
Koha ILS suffers from cross site request forgery, cross site scripting, remote SQL injection, and path traversal vulnerabilities. Versions 3.20.x less than or equal to 3.20.1, 3.18.x less than or equal to 3.18.8, and 3.16.x less than or equal to 3.16.12 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-06-16 CVE Reserved
- 2015-06-26 CVE Published
- 2015-06-26 First Exploit
- 2024-08-06 CVE Updated
- 2025-01-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
https://koha-community.org/koha-3-14-16-released | Release Notes | |
https://koha-community.org/security-release-koha-3-16-12 | Release Notes | |
https://koha-community.org/security-release-koha-3-18-8 | Release Notes | |
https://koha-community.org/security-release-koha-3-20-1 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.14.00 < 3.14.16 Search vendor "Koha" for product "Koha" and version " >= 3.14.00 < 3.14.16" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.16.00 < 3.16.12 Search vendor "Koha" for product "Koha" and version " >= 3.16.00 < 3.16.12" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.18.00 < 3.18.08 Search vendor "Koha" for product "Koha" and version " >= 3.18.00 < 3.18.08" | - |
Affected
| ||||||
Koha Search vendor "Koha" | Koha Search vendor "Koha" for product "Koha" | >= 3.20.00 < 3.20.01 Search vendor "Koha" for product "Koha" and version " >= 3.20.00 < 3.20.01" | - |
Affected
|