HIGH
KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in /cgi-bin/koha/members/paycollect.pl Parameters affected: borrowernumber, amount, amountoutstanding, paid that can result in Attackers can mark payments as paid for certain users on behalf of Administrators
Published Sep 6, 2018
8.8
HIGHCVSS 3.0
EPSS 0.48%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.