CVE-2015-4633 describes multiple critical SQL injection vulnerabilities in various versions of the Koha integrated library system (3.14.x, 3.16.x, 3.18.x, and 3.20.x). Attackers can exploit these flaws through the OPAC interface via the number parameter or, for authenticated users, through the Staff interface using the Filter or Criteria parameters. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, exploit code is publicly available on ExploitDB, and the CVE has garnered significant community discussion, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.14.00, < 3.14.16CPE matchmatch criteria | cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* | ||
>= 3.16.00, < 3.16.12CPE matchmatch criteria | cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* | ||
>= 3.18.00, < 3.18.08CPE matchmatch criteria | cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* | ||
>= 3.20.00, < 3.20.01CPE matchmatch criteria | cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.