CyberRota Analysis
AI-GeneratedKoha's circulation statistics report is vulnerable to SQL injection due to the unsafe concatenation of user-controlled parameters in its query construction. This flaw allows an authenticated staff user with reports module permissions to execute arbitrary SQL commands, potentially exposing sensitive data such as borrower information, password hashes, and API keys. Organizations using Koha should prioritize remediation to protect against unauthorized data access and potential breaches.
Original NVD Description
Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding.