SQL Injection Vulnerability in Koha Library Software by Koha Community
CVE-2023-44961
7.5HIGH
Key Information:
- Vendor
Koha-community
- Status
- Vendor
- CVE Published:
- 11 October 2023
Badges
👾 Exploit Exists
What is CVE-2023-44961?
A SQL Injection vulnerability exists in Koha Library Software versions 23.0.5.04 and earlier, specifically in the intranet/cgi-bin/cataloging/ysearch.pl component. This flaw enables a remote attacker to execute unauthorized SQL queries, potentially exposing sensitive information stored within the system. Users of affected versions should take immediate action to mitigate risks associated with this vulnerability.
