CVE-2025-52360: XSS
A Cross-Site Scripting (XSS) vulnerability exists in the OPAC search feature of Koha Library Management System v24.05. Unsanitized input entered in the search field is reflected in the search history interface, leading to the execution of arbitrary JavaScript in the browser context when the user interacts with the interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52360?
CVE-2025-52360 is classified as a medium-severity Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-52360?
To mitigate CVE-2025-52360, sanitize user input in the OPAC search feature to prevent arbitrary JavaScript execution.
Who is affected by CVE-2025-52360?
CVE-2025-52360 affects users of Koha Library Management System v24.05.
What kind of attack can occur through CVE-2025-52360?
CVE-2025-52360 allows attackers to inject malicious JavaScript into the browser context of users accessing the search history interface.
When was CVE-2025-52360 disclosed?
CVE-2025-52360 was disclosed in the year 2025.