CVE-2024-24337: High severity Koha Koha vulnerability
CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24337?
CVE-2024-24337 is a vulnerability that can lead to CSV Injection, which is considered a medium severity risk.
How do I fix CVE-2024-24337?
To fix CVE-2024-24337, you should upgrade to Koha Library Management System version 23.05.06 or later.
Which endpoints are affected by CVE-2024-24337?
CVE-2024-24337 affects the '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System.
What types of attacks can CVE-2024-24337 enable?
CVE-2024-24337 allows attackers to inject DDE commands into CSV exports, potentially compromising data integrity.
Who is impacted by CVE-2024-24337?
Users of Koha Library Management System version 23.05.05 and earlier are impacted by CVE-2024-24337.