← Back to CVE List

CVE-2015-4633

Published: 2018-10-18T21:29Z
Last Modified: 2024-11-21T02:31Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt