Cross-Site Scripting Vulnerability in Koha Library Management System
CVE-2025-52360
8.8HIGH
What is CVE-2025-52360?
A Cross-Site Scripting (XSS) vulnerability has been identified in the OPAC search feature of the Koha Library Management System version 24.05. This flaw allows attackers to inject malicious scripts through unsanitized inputs in the search field, which are reflected in the search history interface. Consequently, when users interact with this interface, arbitrary JavaScript can be executed within their browsers, potentially compromising their session and sensitive information.
