PT-2026-52983 · Unknown · Library Management System

·

CVE-2026-50767

·

Published

2026-06-26

·

Updated

2026-07-01

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Koha Library Management System versions 0 through 25.11
Description A stored cross-site scripting (XSS) issue exists in the item type administration page. An authenticated remote attacker with administrator privileges can inject arbitrary web scripts through the checkinmsg field. Stored XSS occurs when a malicious script is permanently stored on the target server and later executed in the browser of another user.
Recommendations Update Koha Library Management System to a version later than 25.11. As a temporary mitigation, restrict administrative access to the item type administration page and avoid entering untrusted content into the checkinmsg field.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50767

Affected Products

Library Management System