CVE-2015-4633: SQL Injection
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tagssubject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowersout.pl in the Staff interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-4633?
CVE-2015-4633 is a vulnerability in Koha, allowing remote attackers to execute arbitrary SQL commands.
How severe is CVE-2015-4633?
CVE-2015-4633 has a severity rating of 9.8 (critical).
Which versions of Koha are affected by CVE-2015-4633?
Koha versions 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 are affected by CVE-2015-4633.
How can remote attackers exploit CVE-2015-4633?
Remote attackers can exploit CVE-2015-4633 by sending a malicious number parameter to opac-tags_subject.pl in the OPAC interface.
Where can I find more information about CVE-2015-4633?
You can find more information about CVE-2015-4633 in the following references: [link1](https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14412), [link2](https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14426), [link3](https://koha-community.org/koha-3-14-16-released/).