← Back to search

CVE-2026-70373

8.8 HIGH

Published 2026-08-04 · Updated 2026-08-10

AI risk analysis

Summary
The flaw allows for SQL injection by directly concatenating user-controlled parameters into SQL queries, leading to potential data compromise, manipulation, and system disruption.
Exploitability
Exploitation is relatively straightforward given the direct SQL injection vulnerability, requiring only that the attacker control the input parameters.
Blast radius
If exploited, this could result in unauthorized data access, manipulation, or deletion, affecting the integrity and confidentiality of the Koha database.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of Koha, specifically version 4.21.1 or later, which includes the necessary security patches.
sql-injectionrcewebdatabase

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.