← Back to search

CVE-2026-70369

8.8 HIGH

Published 2026-08-04 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows an attacker to inject SQL commands by manipulating user-controlled Filter request parameters, leading to potential data manipulation or system compromise.
Exploitability
Exploitation is moderately hard as it requires crafting specific SQL injection payloads, and the attacker must have the ability to control the Filter request parameters.
Blast radius
If exploited, the impact could be high, potentially allowing an attacker to manipulate database queries and access sensitive information or execute arbitrary SQL commands.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of Koha, specifically version 4.20.0 or later, as this addresses the SQL injection vulnerability.
sql-injectionwebrce

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, items.homebranch, items.ccode, biblioitems.itemtype, aqbudgets.budget_code, aqorders.sort1, and aqorders.sort2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.