CVE-2026-6428

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-13 17:16

Updated : 2026-08-10 12:17


NVD link : CVE-2026-6428

Mitre link : CVE-2026-6428

CVE.ORG link : CVE-2026-6428


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')