CVE-2024-28739: Command Injection
Published Aug 6, 2024
·Updated
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
Affected Software
1 affected component
Koha Koha<=23.05.00
Event History
Aug 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28739?
CVE-2024-28739 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-28739?
To fix CVE-2024-28739, you should upgrade Koha ILS to version 23.06 or later.
3
Who is affected by CVE-2024-28739?
Organizations using Koha ILS version 23.05 and earlier are affected by CVE-2024-28739.
4
What type of vulnerability is CVE-2024-28739?
CVE-2024-28739 is a remote code execution vulnerability caused by improper handling of input.
5
Can CVE-2024-28739 be exploited remotely?
Yes, CVE-2024-28739 can be exploited remotely by an attacker sending a crafted request.