Cross-Site Scripting in Koha Library Management System by Koha Community
CVE-2026-50765
6.1MEDIUM
What is CVE-2026-50765?
A Cross-Site Scripting (XSS) vulnerability exists in the patron restriction type administration page of the Koha Library Management System. This flaw allows an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field), potentially compromising the security of the application and its users. Without proper input sanitization, malicious scripts could be executed in the context of an affected user, leading to further exploitation.
