Cross-Site Scripting Vulnerabilities in Koha Library Software
CVE-2015-4631
5.4MEDIUM
Summary
Multiple vulnerabilities in Koha ILS allow remote attackers to exploit various parameters across different scripts, leading to the injection of arbitrary web scripts or HTML. This exposure enables the manipulation of the web application, potentially compromising user sessions, stealing sensitive information, or redirecting users to malicious sites. The affected scripts span various functionalities such as search operations and suggestion submissions, thereby exposing a wide attack surface for potential intrusions.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved