Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Koha-community
Koha-community koha |
|
| Vendors & Products |
Koha-community
Koha-community koha |
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary SQL via the image_name field of a patron card layout. The image_name value is stored verbatim in the layout XML and later concatenated raw into a SQL query in patroncards/create-pdf.pl when a patron card batch is printed. An attacker can read the entire Koha database including patron PII and staff bcrypt password hashes via error-based or time-based blind injection. | |
| Title | Koha Community Koha - Stored SQL Injection via Patron Card Layout image_name | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:07:56.368Z
Reserved: 2026-08-10T10:33:03.258Z
Link: CVE-2026-72608
Updated: 2026-08-11T12:07:43.847Z
Status : Received
Published: 2026-08-11T12:17:43.987
Modified: 2026-08-11T13:19:04.843
Link: CVE-2026-72608
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:00:10Z