8

CVE-2015-4630

Exploit
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KohaKoha Version >= 3.14.00 < 3.14.16
KohaKoha Version >= 3.16.00 < 3.16.12
KohaKoha Version >= 3.18.0 < 3.18.8
KohaKoha Version >= 3.20.00 < 3.20.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.97% 0.855
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8 2.1 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

https://koha-community.org/koha-3-14-16-released/
Vendor Advisory
Product
Release Notes
https://koha-community.org/security-release-koha-3-16-12/
Vendor Advisory
Product
Release Notes
https://koha-community.org/security-release-koha-3-20-1/
Vendor Advisory
Product
Release Notes
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14423
Vendor Advisory
Exploit
Issue Tracking
https://koha-community.org/security-release-koha-3-18-8/
Vendor Advisory
Product
Release Notes
https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html
Third Party Advisory
Exploit
VDB Entry
https://seclists.org/fulldisclosure/2015/Jun/80
Third Party Advisory
Exploit
Mailing List
https://www.exploit-db.com/exploits/37389/
Third Party Advisory
VDB Entry
https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-the-koha-library-software-via-combinatorial-testing/
Third Party Advisory