CVE-2024-28740: XSS
Published Aug 6, 2024
·Updated
Cross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl component.
Affected Software
1 affected component
Koha Koha<=23.05.00
Event History
Aug 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-28740?
CVE-2024-28740 is rated as a high-severity vulnerability due to its ability to allow remote code execution.
2
How do I fix CVE-2024-28740?
To fix CVE-2024-28740, upgrade Koha ILS to version 23.06 or later, which includes patches for this vulnerability.
3
What is the impact of CVE-2024-28740?
CVE-2024-28740 allows attackers to execute arbitrary code, potentially leading to unauthorized access and data compromise.
4
Which versions of Koha ILS are affected by CVE-2024-28740?
CVE-2024-28740 affects Koha ILS versions 23.05 and earlier.
5
Who is at risk from CVE-2024-28740?
Organizations using Koha ILS versions up to 23.05 are at risk from CVE-2024-28740 due to the cross-site scripting vulnerability.