CVE-2015-4630: XSS
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-4630?
CVE-2015-4630 is a vulnerability in Koha versions 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 that allows remote attackers to hijack the authentication of administrators to create a user.
How severe is CVE-2015-4630?
CVE-2015-4630 is considered a high severity vulnerability with a severity value of 8.
How can I fix CVE-2015-4630?
To fix CVE-2015-4630, update your Koha software to versions 3.14.16, 3.16.12, 3.18.08, or 3.20.1 or later.
What is the Common Weakness Enumeration (CWE) ID for CVE-2015-4630?
CVE-2015-4630 is associated with CWE-79 and CWE-352.
Where can I find more information about CVE-2015-4630?
More information about CVE-2015-4630 can be found at the following references: [1](https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14423), [2](https://koha-community.org/koha-3-14-16-released/), [3](https://koha-community.org/security-release-koha-3-16-12/).