PT-2020-7613 · Koha · Koha

Galen Charlton

·

Published

2020-01-24

·

Updated

2020-01-30

·

CVE-2014-1924

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Koha versions prior to 3.8.23 Koha versions 3.10.x prior to 3.10.13 Koha versions 3.12.x prior to 3.12.10 Koha versions 3.14.x prior to 3.14.3
Description The issue concerns the MARC framework import/export function, specifically the admin/import export framework.pl script, which does not require authentication. This lack of authentication allows remote attackers to conduct SQL injection attacks.
Recommendations For Koha versions prior to 3.8.23, update to version 3.8.23 or later. For Koha versions 3.10.x prior to 3.10.13, update to version 3.10.13 or later. For Koha versions 3.12.x prior to 3.12.10, update to version 3.12.10 or later. For Koha versions 3.14.x prior to 3.14.3, update to version 3.14.3 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1924

Affected Products

Koha