VYPR
High severity7.6NVD Advisory· Published Jun 13, 2026· Updated Aug 10, 2026

CVE-2026-6428

CVE-2026-6428

Description

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Koha/Kohainferred2 versions
    <26.11.00+ 1 more
    • (no CPE)range: <26.11.00
    • (no CPE)range: <=22.11.37, 23.x, 24.x<24.11.16, 25.05.x<25.05.11, 25.11.x<25.11.05, 26.05.x<26.05.01, 26.11.x<26.11.00

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.