peter bassill · operator
$ cve CVE-2015-4633 JSON

CVE-2015-4633 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 6.1% (pctl 93)

Patch early

A public exploit exists.

Description

Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.07% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2018-10-18
Last modified2026-06-17

Affected (1)

VendorProduct
kohakoha

Public exploits

SourceTitleDate
exploit-dbKoha 3.20.1 - Multiple SQL Injections2015-06-26

References

→ the Explorer  ·  watch your stack  ·  NVD