Remote Command Execution Vulnerability in Koha Library Management System
CVE-2025-30076
What is CVE-2025-30076?
The Koha Library Management System is affected by a vulnerability that allows administrators to execute arbitrary commands through the manipulation of shell metacharacters in the tools/scheduler.pl report parameter. This issue can lead to serious security breaches if exploited, as it provides an attacker with the capability to run unauthorized commands on the server, potentially compromising the integrity and confidentiality of the system. To secure your installation, it is crucial to update to the latest version of Koha that addresses this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Koha 0 < 22.11.24
Koha 23 < 23.11.12
Koha 24 < 24.05.07
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
