Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, items.homebranch, items.ccode, biblioitems.itemtype, aqbudgets.budget_code, aqorders.sort1, and aqorders.sort2.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-04 13:18
Updated : 2026-08-26 17:36
NVD link : CVE-2026-70369
Mitre link : CVE-2026-70369
CVE.ORG link : CVE-2026-70369
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
