THREAT OPS › Threat News › [NVD] CVE-2026-70372 (HIGH 8.8) — Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable
[NVD] CVE-2026-70372 (HIGH 8.8) — Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable
CVE-2026-70372 CVSS: 8.8 HIGH Published: 2026-08-04T13:18:58.040
Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (passw
Indicators of compromise
- CVE-2026-70372cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70372