CVE-2024-36058

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.
Configurations

No configuration.

History

No history.

Information

Published : 2026-04-07 17:16

Updated : 2026-06-17 07:36


NVD link : CVE-2024-36058

Mitre link : CVE-2024-36058

CVE.ORG link : CVE-2024-36058


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')