CVE-2025-22954: SQL Injection
Published Mar 12, 2025
·Updated
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
Affected Software
1 affected component
Koha Koha<24.11.02
Event History
Mar 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22954?
CVE-2025-22954 has been rated as a medium severity vulnerability due to its potential for SQL injection.
2
How do I fix CVE-2025-22954?
To fix CVE-2025-22954, upgrade Koha to version 21.12 or later where the vulnerability has been addressed.
3
What impact does CVE-2025-22954 have on affected systems?
Successful exploitation of CVE-2025-22954 can allow attackers to execute arbitrary SQL queries on the database.
4
Which versions of Koha are affected by CVE-2025-22954?
CVE-2025-22954 affects Koha versions up to and including 21.11.
5
How can I identify if my Koha installation is vulnerable to CVE-2025-22954?
You can identify if your installation is vulnerable by checking if you are running Koha version 21.11 or earlier and reviewing the affected scripts like /serials/lateissues-export.pl.