CVE-2014-1924

CRITICAL

Koha <3.8.23, <3.10.13, <3.12.10, <3.14.3 - SQL Injection

Title source: llm
STIX 2.1

Description

The MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 does not require authentication, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

References (4)

Core 4
Core References
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2014/02/07/10
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2014/02/10/3
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=11666

Scores

CVSS v3 9.8
EPSS 0.0204
EPSS Percentile 79.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
koha/koha < 3.08.23
Published Jan 24, 2020
Tracked Since Feb 18, 2026