High severity8.0NVD Advisory· Published Feb 12, 2024· Updated Jun 17, 2026
CVE-2024-24337
CVE-2024-24337
Description
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Koha/Koha Library Management Systemdescription
- Range: <=23.05.05
- Range: <=23.05.05
Patches
Vulnerability mechanics
References
2- nitipoom-jar.github.io/CVE-2024-24337/nvdExploitThird Party Advisory
- nitipoom-jaroonchaipipat.github.io/security-research-portal/2024-24337nvd
News mentions
0No linked articles in our index yet.