Логотип exploitDog
bind:CVE-2026-31844
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-31844

Количество 3

Количество 3

nvd логотип

CVE-2026-31844

19 дней назад

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL queries via crafted requests to this parameter, allowing execution of unintended SQL statements and exposure of sensitive database information. Successful exploitation may lead to full compromise of the backend database, including disclosure or modification of stored data.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2026-31844

19 дней назад

An authenticated SQL Injection vulnerability (CWE-89) exists in the Ko ...

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-x6wm-w6mm-jpf2

19 дней назад

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL queries via crafted requests to this parameter, allowing execution of unintended SQL statements and exposure of sensitive database information. Successful exploitation may lead to full compromise of the backend database, including disclosure or modification of stored data.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-31844

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL queries via crafted requests to this parameter, allowing execution of unintended SQL statements and exposure of sensitive database information. Successful exploitation may lead to full compromise of the backend database, including disclosure or modification of stored data.

CVSS3: 8.8
0%
Низкий
19 дней назад
debian логотип
CVE-2026-31844

An authenticated SQL Injection vulnerability (CWE-89) exists in the Ko ...

CVSS3: 8.8
0%
Низкий
19 дней назад
github логотип
GHSA-x6wm-w6mm-jpf2

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL queries via crafted requests to this parameter, allowing execution of unintended SQL statements and exposure of sensitive database information. Successful exploitation may lead to full compromise of the backend database, including disclosure or modification of stored data.

CVSS3: 8.8
0%
Низкий
19 дней назад

Уязвимостей на страницу