Remote Command Execution Vulnerability in Koha Library Management System
CVE-2025-30076

7.7HIGH

Key Information:

Vendor
Koha
Status
Vendor
CVE Published:
16 March 2025

Summary

The Koha Library Management System is affected by a vulnerability that allows administrators to execute arbitrary commands through the manipulation of shell metacharacters in the tools/scheduler.pl report parameter. This issue can lead to serious security breaches if exploited, as it provides an attacker with the capability to run unauthorized commands on the server, potentially compromising the integrity and confidentiality of the system. To secure your installation, it is crucial to update to the latest version of Koha that addresses this flaw.

Affected Version(s)

Koha 0 < 22.11.24

Koha 23 < 23.11.12

Koha 24 < 24.05.07

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.