HIGH

CVE-2026-70372

2026-08-04 CVSS v3.1
CVSS
8.8

Description

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

0.31%
Probability of exploitation in next 30 days
23.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE