CVE-2014-9446: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Staff client in Koha before 3.16.6 and 3.18.x before 3.18.2 allow remote attackers to inject arbitrary web script or HTML via the sortby parameter to the (1) opac parameter in opac-search.pl or (2) intranet parameter in catalogue/search.pl.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9446?
CVE-2014-9446 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-9446?
To fix CVE-2014-9446, upgrade to Koha version 3.16.6 or later, or 3.18.2 or later.
What software versions are affected by CVE-2014-9446?
CVE-2014-9446 affects Koha versions before 3.16.6 and version 3.18.x before 3.18.2.
What are the potential consequences of CVE-2014-9446?
Exploitation of CVE-2014-9446 could allow remote attackers to inject arbitrary web scripts or HTML into affected applications.
Is there a workaround for CVE-2014-9446?
There are no documented workarounds for CVE-2014-9446; applying the patch is the recommended approach.