Cross-Site Scripting Vulnerability in Koha Library Management System
CVE-2025-52360

8.8HIGH

Key Information:

Vendor

Koha

Vendor
CVE Published:
25 July 2025

What is CVE-2025-52360?

A Cross-Site Scripting (XSS) vulnerability has been identified in the OPAC search feature of the Koha Library Management System version 24.05. This flaw allows attackers to inject malicious scripts through unsanitized inputs in the search field, which are reflected in the search history interface. Consequently, when users interact with this interface, arbitrary JavaScript can be executed within their browsers, potentially compromising their session and sensitive information.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.