THREAT OPS › Threat News › [NVD] CVE-2026-31844 (HIGH 8.8) — An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to f
[NVD] CVE-2026-31844 (HIGH 8.8) — An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to f
CVE-2026-31844 CVSS: 8.8 HIGH Published: 2026-03-11T07:16:43.900
An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. Successful exploitation may lead to full compromise of the backend database, including disc
Indicators of compromise
- CVE-2026-31844cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-31844