PT-2026-52983 · Unknown · Library Management System
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Koha Library Management System versions 0 through 25.11
Description
A stored cross-site scripting (XSS) issue exists in the item type administration page. An authenticated remote attacker with administrator privileges can inject arbitrary web scripts through the
checkinmsg field. Stored XSS occurs when a malicious script is permanently stored on the target server and later executed in the browser of another user.Recommendations
Update Koha Library Management System to a version later than 25.11.
As a temporary mitigation, restrict administrative access to the item type administration page and avoid entering untrusted content into the
checkinmsg field.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Library Management System