SQL Injection Vulnerabilities in Koha Library Software
CVE-2015-4633
9.8CRITICAL
What is CVE-2015-4633?
Multiple SQL injection vulnerabilities exist in versions of Koha prior to specific updates, allowing remote attackers to execute arbitrary SQL commands through crafted parameters in certain OPAC and Staff interface scripts. These weaknesses can be exploited by unauthenticated and authenticated users, posing significant risks to the integrity of the application's database.
