Cross-Site Scripting Vulnerabilities in Koha Library Software
CVE-2015-4631

5.4MEDIUM

Key Information:

Vendor
Koha
Status
Vendor
CVE Published:
18 October 2018

Summary

Multiple vulnerabilities in Koha ILS allow remote attackers to exploit various parameters across different scripts, leading to the injection of arbitrary web scripts or HTML. This exposure enables the manipulation of the web application, potentially compromising user sessions, stealing sensitive information, or redirecting users to malicious sites. The affected scripts span various functionalities such as search operations and suggestion submissions, thereby exposing a wide attack surface for potential intrusions.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.