CVE-2023-5025: KOHA MARC search.pl cross site scripting
A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown code of the file /cgi-bin/koha/catalogue/search.pl of the component MARC. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239866 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5025?
The severity of CVE-2023-5025 is medium with a score of 5.4.
How does CVE-2023-5025 affect KOHA up to version 23.05.03?
CVE-2023-5025 affects KOHA up to version 23.05.03 through the cross site scripting vulnerability in the /cgi-bin/koha/catalogue/search.pl component of the MARC.
Can CVE-2023-5025 be exploited remotely?
Yes, CVE-2023-5025 can be exploited remotely.
What is the CWE of CVE-2023-5025?
The CWE of CVE-2023-5025 is 79.
How can I fix CVE-2023-5025?
To fix CVE-2023-5025, it is recommended to update to a version of KOHA that is not affected by the vulnerability.