Exploitation Summary
EIP tracks 2 public exploits for CVE-2026-31844. PoCs published by XiaomingX, Mothra-1.
AI-analyzed exploit summary This repository contains a Python-based scanner for CVE-2026-31844, an authenticated SQL injection vulnerability in Koha Library Management System. The scanner uses a Boolean-Based Blind technique to detect the vulnerability without exploiting it.
Description
An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A low-privileged staff user can inject arbitrary SQL queries via crafted requests to this parameter, allowing execution of unintended SQL statements and exposure of sensitive database information. Successful exploitation may lead to full compromise of the backend database, including disclosure or modification of stored data.
Exploits (2)
This repository contains a Python-based scanner for CVE-2026-31844, an authenticated SQL injection vulnerability in Koha Library Management System. The scanner uses a Boolean-Based Blind technique to detect the vulnerability without exploiting it.
This repository contains a scanner for CVE-2026-31844, an authenticated SQL injection vulnerability in Koha Library Management System. The scanner uses a Boolean-Based Blind technique to detect the vulnerability without exploiting it.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H