Stored Cross-Site Scripting in Koha Affected by Unsanitized Input
CVE-2026-41921
5.1MEDIUM
What is CVE-2026-41921?
Koha Integrated Library System versions prior to 26.05.02, 25.11.07, and 25.05.13 exhibit a stored cross-site scripting vulnerability in the purchase suggestion handler. This issue enables authenticated staff users to inject malicious scripts through unsanitized input during the suggestion save process. Attackers can enter harmful HTML or script content in various fields, including title, author, ISBN, publisher code, place, collection title, item type, and note. These inputs are stored without proper sanitization, leading to potential script execution in the browsers of any staff user reviewing the suggestions.
Affected Version(s)
Koha 26.05.0
Koha 26.05.0 < 26.05.02
Koha 25.11.0 < 25.11.07
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams from Pellera Technologies
VulnCheck
