AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-70373

HIGH · CVSS 8.8 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Koha's circulation statistics report is vulnerable to SQL injection due to the unsafe concatenation of user-controlled parameters in its query construction. This flaw allows an authenticated staff user with reports module permissions to execute arbitrary SQL commands, potentially exposing sensitive data such as borrower information, password hashes, and API keys. Organizations using Koha should prioritize remediation to protect against unauthorized data access and potential breaches.

CVE
CVE-2026-70373
Severity
HIGH
CVSS
8.8
EPSS
0.31%

Original NVD Description

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding.