Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts …
Medium CVSS 5.4
Summary
Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious scripts by submitting unsanitized input through the suggestion save operation. Attackers can supply crafted HTML or script content in fields such as title, author, isbn, publishercode, place, collectiontitle, itemtype, and note, which are stored without sanitization and later rendered in the suggestion list…
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://koha-community.org/koha-25-05-13-released/
- https://koha-community.org/koha-25-11-07-released/
- https://koha-community.org/koha-26-05-02-released/
- https://www.vulncheck.com/advisories/koha-stored-xss-via-purchase-suggestion-handler
Timeline
- nvd_ingest NVD