« Volver al listado

CVE-2026-6428

Estado: Pendiente de análisisMedia (5.6)—

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-6428",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-6428",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-15T17:19:10.550362Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:C/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 7.8,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.6,
          "Automatable": "YES",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "CONCENTRATED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:Amber",
          "exploitMaturity": "PROOF_OF_CONCEPT",
          "providerUrgency": "AMBER",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
      "affectedData": [
        {
          "repo": "https://gitlab.com/koha-community/Koha",
          "vendor": "Koha Community",
          "product": "Koha",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "semver",
              "lessThanOrEqual": "22.11.38"
            },
            {
              "status": "affected",
              "version": "23.05.00",
              "versionType": "semver",
              "lessThanOrEqual": "23.11.15"
            },
            {
              "status": "affected",
              "version": "24.05.00",
              "versionType": "semver",
              "lessThanOrEqual": "24.11.16"
            },
            {
              "status": "affected",
              "version": "25.05.00",
              "versionType": "semver",
              "lessThanOrEqual": "25.05.11"
            },
            {
              "status": "affected",
              "version": "25.11.00",
              "versionType": "semver",
              "lessThanOrEqual": "25.11.05"
            },
            {
              "status": "affected",
              "version": "26.05.00",
              "versionType": "semver",
              "lessThanOrEqual": "26.05.01"
            }
          ],
          "programFiles": [
            "reports/catalogue_out.pl"
          ],
          "collectionURL": "https://koha-community.org/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-13T17:16:17.190",
  "references": [
    {
      "url": "https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=199539",
      "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"
    },
    {
      "url": "https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42361",
      "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"
    },
    {
      "url": "https://koha-community.org/security-releases/",
      "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/."
    },
    {
      "lang": "es",
      "value": "Inyección SQL en reports/catalogue_out.pl en Koha Community Koha hasta 22.11.37, 23.x, 24.x antes de 24.11.16, 25.05.x antes de 25.05.11, 25.11.x antes de 25.11.05, 26.05.x antes de 26.05.01, y 26.11.x antes de 26.11.00 permite a un usuario de personal autenticado con el indicador del módulo de Informes leer datos arbitrarios de la base de datos de la aplicación Koha a través del parámetro URL Filter cuando el parámetro Criteria coincide con /branchcode/.\n\nEl sumidero vulnerable en la subrutina calculate concatena el parámetro de solicitud Filter sin modificar directamente en una cláusula LIKE de la sentencia auxiliar $strsth2 y lo ejecuta a través de DBI sin parámetros vinculados:\n\nmy $f = @$filters[0];\n$f =~ s/\\*/%/g;\n$strsth2 .= \" AND $column LIKE '$f' \";\n\nEsto permite la inyección SQL basada en errores (por ejemplo, a través de EXTRACTVALUE) y acceso de lectura completo a tablas sensibles incluyendo borrowers (hashes de contraseñas, secretos 2FA, PII), borrower_password_recovery, api_keys, y sessions.\n\nPrueba de concepto (basado en errores, solicitud única):\n\nGET /cgi-bin/koha/reports/catalogue_out.pl?do_it=1&output=screen&Limit=10&Criteria=branchcode&Filter=x'+AND+EXTRACTVALUE(1,CONCAT(0x7e,VERSION(),0x7c,USER(),0x7c,DATABASE(),0x7e))--+-\nCookie: CGISESSID=<LIBRARIAN_SESSION>\n\nEl cuerpo de la respuesta contiene la excepción DBI filtrando la versión de MariaDB, el usuario de la base de datos, la IP del cliente, y el nombre de la base de datos, después de lo cual se pueden paginar datos arbitrarios usando LIMIT n,1 / SUBSTRING(...).\n\nEl sumidero vulnerable fue introducido en el commit 6bb77ae3e4 (2008-07-09); CVE-2015-4633 parcheó la misma clase en archivos hermanos pero no generalizó la corrección a reports/catalogue_out.pl. Corregido en Koha 22.11.38, 24.11.16, 25.05.11, 25.11.05, 26.05.01, y 26.11.00 reemplazando la concatenación cruda con un marcador de posición parametrizado."
    }
  ],
  "lastModified": "2026-08-10T12:17:22.160",
  "sourceIdentifier": "309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c"
}