CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.0. See the original NVD description below for full technical details.
CVE
CVE-2024-24337
Severity
HIGH
CVSS
8
EPSS
0.81%
Original NVD Description
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.
Related CVEs
Other vulnerabilities affecting the same vendor(s)