Critical severity9.8NVD Advisory· Published Oct 18, 2018· Updated Jun 17, 2026
CVE-2015-4633
CVE-2015-4633
Description
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3>=3.14,<3.14.16 || >=3.16,<3.16.12 || >=3.18,<3.18.08 || >=3.20,<3.20.1+ 2 more
- (no CPE)range: >=3.14,<3.14.16 || >=3.16,<3.16.12 || >=3.18,<3.18.08 || >=3.20,<3.20.1
- cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:*range: >=3.14.00,<3.14.16
- (no CPE)range: 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1
Patches
Vulnerability mechanics
References
10- bugs.koha-community.org/bugzilla3/show_bug.cginvdExploitIssue Tracking
- bugs.koha-community.org/bugzilla3/show_bug.cginvdExploitIssue TrackingThird Party Advisory
- packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2015/Jun/80nvdExploitMailing ListThird Party Advisory
- www.exploit-db.com/exploits/37387/nvdExploitThird Party AdvisoryVDB Entry
- www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-the-koha-library-software-via-combinatorial-testing/nvdExploitRelease NotesThird Party Advisory
- koha-community.org/koha-3-14-16-released/nvdRelease Notes
- koha-community.org/security-release-koha-3-16-12/nvdRelease Notes
- koha-community.org/security-release-koha-3-18-8/nvdRelease Notes
- koha-community.org/security-release-koha-3-20-1/nvdRelease Notes
News mentions
0No linked articles in our index yet.