Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter
Published Jun 13, 2026
5.6
MEDIUMCVSS 4.0
EPSS 0.38%
Description
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.
Affected products
-
Affected
- ≥ 0, ≤ 22.11.38
- ≥ 23.05.00, ≤ 23.11.15
- ≥ 24.05.00, ≤ 24.11.16
- ≥ 25.05.00, ≤ 25.05.11
- ≥ 25.11.00, ≤ 25.11.05
- ≥ 26.05.00, ≤ 26.05.01
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Koha Community | Koha | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=199539 patchvendor-advisory
- https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42361 issue-trackingvendor-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36652 Advisory
- https://koha-community.org/security-releases/ vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=199539 | patchvendor-advisory | |
| https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42361 | issue-trackingvendor-advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36652 | Advisory | |
| https://koha-community.org/security-releases/ | vendor-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data