CVE-2014-1925: SQL Injection
SQL injection vulnerability in the MARC framework import/export function (admin/importexportframework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be leveraged by remote attackers using CVE-2014-1924.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2014-1925.
What is the severity score of CVE-2014-1925?
The severity score of CVE-2014-1925 is 9.8 (Critical).
What is the affected software of CVE-2014-1925?
The affected software of CVE-2014-1925 is Koha versions before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3.
How does CVE-2014-1925 occur?
CVE-2014-1925 occurs due to a SQL injection vulnerability in the MARC framework import/export function in Koha.
Are there any references available for CVE-2014-1925?
Yes, you can find references for CVE-2014-1925 at the following links: [Reference 1](http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=11666), [Reference 2](http://koha-community.org/security-release-february-2014/), [Reference 3](http://www.openwall.com/lists/oss-security/2014/02/07/10).