CVE-2014-1924: SQL Injection
The MARC framework import/export function (admin/importexportframework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 does not require authentication, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-1924?
CVE-2014-1924 is a vulnerability that allows remote attackers to conduct SQL injection attacks via the MARC framework import/export function in Koha before version 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3.
How severe is CVE-2014-1924?
CVE-2014-1924 has a severity rating of 9.8 (Critical).
How does CVE-2014-1924 affect Koha?
CVE-2014-1924 affects Koha versions before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3.
What is the impact of CVE-2014-1924?
CVE-2014-1924 allows remote attackers to conduct SQL injection attacks, compromising the security of the affected Koha software.
How can I mitigate CVE-2014-1924?
To mitigate CVE-2014-1924, it is recommended to update Koha to version 3.8.23, 3.10.x to 3.10.13, 3.12.x to 3.12.10, or 3.14.x to 3.14.3 or later.