CVE-2025-30076: OS Command Injection
Published Mar 16, 2025
·Updated
Koha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.
Affected Software
1 affected component
Koha Koha<24.11.02
Event History
Mar 16, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Mar 15, 57195
Event
via FIRST·08:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-30076?
CVE-2025-30076 has been assigned a severity score that indicates it allows high-risk command execution vulnerabilities.
2
How does CVE-2025-30076 affect Koha users?
CVE-2025-30076 allows unauthorized command execution via shell metacharacters in a specific parameter, putting user systems at risk.
3
How do I fix CVE-2025-30076?
To fix CVE-2025-30076, update Koha to version 24.11.02 or later where this vulnerability is addressed.
4
When was CVE-2025-30076 discovered?
CVE-2025-30076 was reported as a vulnerability affecting earlier versions of Koha before 24.11.02.
5
Who is affected by CVE-2025-30076?
Admins using Koha versions prior to 24.11.02 are affected by CVE-2025-30076 due to the risk of arbitrary command execution.