CVE-2015-4633
Summary
| CVE | CVE-2015-4633 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-18 21:29:00 UTC |
| Updated | 2018-12-06 14:26:00 UTC |
| Description | Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Koha ILS 3.20.x CSRF / XSS / Traversal / SQL Injection ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| Full Disclosure: SBA Research Vulnerability Disclosure - Multiple Critical Vulnerabilities in Koha ILS | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| 14426 – SQL Injection in Staff Client | CONFIRM | bugs.koha-community.org | Exploit, Issue Tracking, Third Party Advisory |
| Security Release – Koha 3.20.1 | Official Website of Koha Library Software | CONFIRM | koha-community.org | Release Notes |
| Security Release – Koha 3.18.8 | Official Website of Koha Library Software | CONFIRM | koha-community.org | Release Notes |
| Researchers of SBA Research found several critical security vulnerabilities in the Koha Library software via Combinatorial Testing | SBA Research | MISC | www.sba-research.org | Exploit, Release Notes, Third Party Advisory |
| Security Release – Koha 3.16.12 | Official Website of Koha Library Software | CONFIRM | koha-community.org | Release Notes |
| Koha 3.20.1 - Multiple SQL Injections - PHP webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| Koha 3.14.16 released | Official Website of Koha Library Software | CONFIRM | koha-community.org | Release Notes |
| 14412 – SQL Injection in OPAC Interface | CONFIRM | bugs.koha-community.org | Exploit, Issue Tracking |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.