Record summary

CVE-2015-4630 has a selected CVSS score of 8.0 (high); EIP currently links 1 catalogued exploit.

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBKoha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery VulnerabilitiesExploitDB exploitby Raschin Tavakoli_ Bernhard Garn_ Peter Aufner & Dimitris SimosNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

10