CVE-2024-24336: CSRF
A multiple Cross-site scripting (XSS) vulnerability in the '/members/moremember.pl', and ‘/members/members-home.pl’ endpoints within Koha Library Management System version 23.05.05 and earlier allows malicious staff users to carry out CSRF attacks, including unauthorized changes to usernames and passwords of users visiting the affected page, via the 'Circulation note' and ‘Patrons Restriction’ components.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24336?
CVE-2024-24336 is classified as a moderate severity Cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-24336?
To fix CVE-2024-24336, upgrade the Koha Library Management System to version 23.05.06 or later.
Which versions of the Koha Library Management System are affected by CVE-2024-24336?
CVE-2024-24336 affects Koha Library Management System version 23.05.05 and earlier.
What are the impacts of CVE-2024-24336?
CVE-2024-24336 allows malicious staff users to perform CSRF attacks and make unauthorized changes to usernames and passwords.
Where can I find more information about CVE-2024-24336?
Detailed information about CVE-2024-24336 can be found on various cybersecurity platforms or databases.