Cross-Site Scripting Vulnerability in Koha from ByWater Solutions
CVE-2015-4639
8.8HIGH
What is CVE-2015-4639?
A vulnerability in the opac-addbybiblionumber.pl component of Koha allows remote attackers to exploit cross-site scripting flaws by injecting arbitrary web scripts or HTML code. This can occur when a crafted list name is submitted, leading to unauthorized access and potential manipulation of user web browsers for malicious purposes. Affected versions include Koha 3.14.x, 3.16.x, and 3.20.x, making it critical for users to upgrade to the patched versions to ensure security against these attacks.
