Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter
Summary
| CVE | CVE-2026-6428 |
|---|---|
| State | PUBLISHED |
| Assigner | TuranSec |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-13 17:16:17 UTC |
| Updated | 2026-08-10 12:17:22 UTC |
| Description | SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/. |
Risk And Classification
Primary CVSS: v4.0 5.6 MEDIUM from 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:Amber
EPSS: 0.002440000 probability, percentile 0.156130000 (date 2026-08-10)
Problem Types: CWE-89 | CWE-89 CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c | Secondary | 5.6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/C... |
| 4.0 | CNA | CVSS | 5.6 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/A... |
| 3.1 | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c | Secondary | 7.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
| 3.1 | CNA | CVSS | 7.6 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
| 2.0 | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c | Secondary | 7.5 | AV:N/AC:L/Au:S/C:C/I:N/A:P | |
| 2.0 | CNA | CVSS | 7.5 | AV:N/AC:L/Au:S/C:C/I:N/A:P |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
PresentPrivileges Required
LowUser Interaction
NoneConfidentiality
HighIntegrity
LowAvailability
LowSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:Amber
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
LowAvailability
LowCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
CompleteIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:S/C:C/I:N/A:P
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Koha Community | Koha | affected 22.11.38 semver | Not specified |
| CNA | Koha Community | Koha | affected 23.05.00 23.11.15 semver | Not specified |
| CNA | Koha Community | Koha | affected 24.05.00 24.11.16 semver | Not specified |
| CNA | Koha Community | Koha | affected 25.05.00 25.05.11 semver | Not specified |
| CNA | Koha Community | Koha | affected 25.11.00 25.11.05 semver | Not specified |
| CNA | Koha Community | Koha | affected 26.05.00 26.05.01 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugs.koha-community.org/bugzilla3/show_bug.cgi | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c | bugs.koha-community.org | |
| bugs.koha-community.org/bugzilla3/attachment.cgi | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c | bugs.koha-community.org | |
| koha-community.org/security-releases | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c | koha-community.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Sanjar Tulkinov (Sanjarbiy) (en)
There are currently no legacy QID mappings associated with this CVE.