{"id":"CVE-2023-5025","summary":"KOHA MARC search.pl cross site scripting","details":"A vulnerability was found in KOHA up to 23.05.03. It has been declared as problematic. This vulnerability affects unknown code of the file /cgi-bin/koha/catalogue/search.pl of the component MARC. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-239866 is the identifier assigned to this vulnerability.","modified":"2026-07-15T01:49:01.250457926Z","published":"2023-09-17T07:00:07.258Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5025.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"23.05.03"},{"last_affected":"23.05.03"}]}],"cna_assigner":"VulDB","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://www.youtube.com/watch?v=b5107YkpgaM"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5025.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5025"},{"type":"ADVISORY","url":"https://vuldb.com/?id.239866"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.239866"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/koha-community/koha","events":[{"introduced":"0"},{"last_affected":"3d05a1aba8cea96f598b8b914892cc59a49b0652"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"23.05.03"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:*"}}],"versions":["v23.05.03","v23.05.02","v23.05.01","v23.05.00","v22.11.00","v22.05.00","v21.11.00","v21.05.00","v20.11.00","v20.05.00","v19.11.00","v19.05.00","v18.11.00","v18.05.00","v18.05.00-rc1","v17.11.00","v17.05.00","v16.11.00","v16.05.00","v16.05.00-beta","v3.22.00","v3.22.00-beta","v3.20.00","v3.20.00-beta","v3.18.00","v3.18.00-beta","v3.16.00","v3.16.00-rc","v3.16.00-beta","v3.14.00-beta","v3.14.00-alpha2","v3.14.00-alpha1","v3.12.00-beta1","v3.12.00-alpha2","v3.12.00-alpha","v3.08.00","v3.04.00","v3.02.00-beta","v3.02.00-alpha2","v3.02.00-alpha","v3.00.00","v3.00.00-stableRC1","v3.00.00-beta2","v3.00.00-beta","v3.00.00-alpha","R_2-4","R_2-1","R_2-0-0RC1","R_2-0-0pre5","R_2-0-0pre4","R_2-0-0pre3","R_2-0-0pre2","R_2-0-0pre1","R_1-9-3","R_1-9-2","R_1-9-1","R_1-9-0","R_1-3-3","R_1-3-2","R_1-3-1","R_1-3-0","R_1-2-2RC4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5025.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"}]}