Cross-Site Scripting in Koha Library Management System by Koha Community
CVE-2026-50765

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 June 2026

What is CVE-2026-50765?

A Cross-Site Scripting (XSS) vulnerability exists in the patron restriction type administration page of the Koha Library Management System. This flaw allows an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field), potentially compromising the security of the application and its users. Without proper input sanitization, malicious scripts could be executed in the context of an affected user, leading to further exploitation.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.