THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70372 (HIGH 8.8) — Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable

[NVD] CVE-2026-70372 (HIGH 8.8) — Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable

mednvdPublished 2026-08-04

CVE-2026-70372 CVSS: 8.8 HIGH Published: 2026-08-04T13:18:58.040

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (passw

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70372