THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-31844 (HIGH 8.8) — An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to f

[NVD] CVE-2026-31844 (HIGH 8.8) — An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to f

lownvdPublished 2026-03-11

CVE-2026-31844 CVSS: 8.8 HIGH Published: 2026-03-11T07:16:43.900

An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to full compromise of the backend database, including disc

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-31844