{"api_version":"1","generated_at":"2026-07-23T08:26:36+00:00","cve":"CVE-2015-4633","urls":{"html":"https://cve.report/CVE-2015-4633","api":"https://cve.report/api/cve/CVE-2015-4633.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-4633","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-4633"},"summary":{"title":"CVE-2015-4633","description":"Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-10-18 21:29:00","updated_at":"2018-12-06 14:26:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html","name":"https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html","refsource":"MISC","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Koha ILS 3.20.x CSRF / XSS / Traversal / SQL Injection ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/fulldisclosure/2015/Jun/80","name":"20150625 SBA Research Vulnerability Disclosure - Multiple Critical Vulnerabilities in Koha ILS","refsource":"FULLDISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"Full Disclosure: SBA Research Vulnerability Disclosure - Multiple Critical Vulnerabilities in Koha ILS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14426","name":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14426","refsource":"CONFIRM","tags":["Exploit","Issue Tracking","Third Party Advisory"],"title":"14426 – SQL Injection in Staff Client","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://koha-community.org/security-release-koha-3-20-1/","name":"https://koha-community.org/security-release-koha-3-20-1/","refsource":"CONFIRM","tags":["Release Notes"],"title":"Security Release – Koha 3.20.1 | Official Website of Koha Library Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://koha-community.org/security-release-koha-3-18-8/","name":"https://koha-community.org/security-release-koha-3-18-8/","refsource":"CONFIRM","tags":["Release Notes"],"title":"Security Release – Koha 3.18.8 | Official Website of Koha Library Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-the-koha-library-software-via-combinatorial-testing/","name":"https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-the-koha-library-software-via-combinatorial-testing/","refsource":"MISC","tags":["Exploit","Release Notes","Third Party Advisory"],"title":"Researchers of SBA Research found several critical security vulnerabilities in the Koha Library software via Combinatorial Testing | SBA Research","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://koha-community.org/security-release-koha-3-16-12/","name":"https://koha-community.org/security-release-koha-3-16-12/","refsource":"CONFIRM","tags":["Release Notes"],"title":"Security Release – Koha 3.16.12 | Official Website of Koha Library Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/37387/","name":"37387","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Koha 3.20.1 - Multiple SQL Injections - PHP webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://koha-community.org/koha-3-14-16-released/","name":"https://koha-community.org/koha-3-14-16-released/","refsource":"CONFIRM","tags":["Release Notes"],"title":"Koha 3.14.16 released | Official Website of Koha Library Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14412","name":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14412","refsource":"CONFIRM","tags":["Exploit","Issue Tracking"],"title":"14412 – SQL Injection in OPAC Interface","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-4633","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-4633","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"4633","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"koha","cpe5":"koha","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"4633","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"koha","cpe5":"koha","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2015-4633","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14426","refsource":"CONFIRM","url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14426"},{"name":"https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html","refsource":"MISC","url":"https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html"},{"name":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14412","refsource":"CONFIRM","url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14412"},{"name":"https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-the-koha-library-software-via-combinatorial-testing/","refsource":"MISC","url":"https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-the-koha-library-software-via-combinatorial-testing/"},{"name":"https://koha-community.org/security-release-koha-3-16-12/","refsource":"CONFIRM","url":"https://koha-community.org/security-release-koha-3-16-12/"},{"name":"37387","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/37387/"},{"name":"20150625 SBA Research Vulnerability Disclosure - Multiple Critical Vulnerabilities in Koha ILS","refsource":"FULLDISC","url":"https://seclists.org/fulldisclosure/2015/Jun/80"},{"name":"https://koha-community.org/security-release-koha-3-18-8/","refsource":"CONFIRM","url":"https://koha-community.org/security-release-koha-3-18-8/"},{"name":"https://koha-community.org/security-release-koha-3-20-1/","refsource":"CONFIRM","url":"https://koha-community.org/security-release-koha-3-20-1/"},{"name":"https://koha-community.org/koha-3-14-16-released/","refsource":"CONFIRM","url":"https://koha-community.org/koha-3-14-16-released/"}]}},"nvd":{"publishedDate":"2018-10-18 21:29:00","lastModifiedDate":"2018-12-06 14:26:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:*","versionStartIncluding":"3.14.00","versionEndExcluding":"3.14.16","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:*","versionStartIncluding":"3.16.00","versionEndExcluding":"3.16.12","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:*","versionStartIncluding":"3.18.00","versionEndExcluding":"3.18.08","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:*","versionStartIncluding":"3.20.00","versionEndExcluding":"3.20.01","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"4633","Ordinal":"81611","Title":"CVE-2015-4633","CVE":"CVE-2015-4633","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"4633","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.","Type":"Description","Title":null},{"CveYear":"2015","CveId":"4633","Ordinal":"2","NoteData":"2018-10-18","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"4633","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}