CVE-2026-6428

Source
https://cve.org/CVERecord?id=CVE-2026-6428
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6428.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6428
Published
2026-06-13T16:34:10.326Z
Modified
2026-08-12T03:51:16.544797707Z
Severity
  • 5.6 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/AU:Y/V:C/U:Amber CVSS Calculator
Summary
Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter
Details

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "22.11.38"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "TuranSec",
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6428.json"
}
References

Affected packages

Git / gitlab.com/koha-community/Koha

Affected ranges

Type
GIT
Repo
https://gitlab.com/koha-community/Koha
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "23.05.00"
        },
        {
            "last_affected": "23.11.15"
        },
        {
            "introduced": "24.05.00"
        },
        {
            "last_affected": "24.11.16"
        },
        {
            "introduced": "25.05.00"
        },
        {
            "last_affected": "25.05.11"
        },
        {
            "introduced": "25.11.00"
        },
        {
            "last_affected": "25.11.05"
        },
        {
            "introduced": "26.05.00"
        },
        {
            "last_affected": "26.05.01"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v23.*
v23.05.00
v23.11.00
v23.11.01
v23.11.02
v23.11.03
v23.11.04
v23.11.04-4
v23.11.05
v23.11.06
v23.11.06-1
v23.11.07
v23.11.08
v23.11.08-1
v23.11.09
v23.11.10
v23.11.11
v23.11.12-1
v23.11.13-1
v23.11.14-1
v23.11.15-1
v24.*
v24.05.00
v24.11.00
v24.11.01
v24.11.02-1
v24.11.03-2
v24.11.03-3
v24.11.04-1
v24.11.05-1
v24.11.06-1
v24.11.07-1
v24.11.08-1
v24.11.08-2
v24.11.08-3
v24.11.09-1
v24.11.10-2
v24.11.11-1
v24.11.11-2
v24.11.12-1
v24.11.13-1
v24.11.14-1
v24.11.16-2
v25.*
v25.05.00-1
v25.05.01-1
v25.05.02-1
v25.05.02-2
v25.05.03-1
v25.05.04-1
v25.05.05-1
v25.05.05-2
v25.05.06-2
v25.05.07-1
v25.05.08-2
v25.05.08-3
v25.05.09-2
v25.05.09-3
v25.05.09-4
v25.05.10-1
v25.05.11-1
v25.11.00
v25.11.00-1
v25.11.00-2
v25.11.01-1
v25.11.01-2
v25.11.02-1
v25.11.03-1
v25.11.03-2
v25.11.04-1
v25.11.05-1
v26.*
v26.05.00
v26.05.01
v26.05.01-1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6428.json"