{"id":"CVE-2024-24337","details":"CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.","modified":"2026-04-10T05:09:48.247124Z","published":"2024-02-12T22:15:08.430Z","references":[{"type":"WEB","url":"https://nitipoom-jaroonchaipipat.github.io/security-research-portal/2024-24337"},{"type":"EVIDENCE","url":"https://nitipoom-jar.github.io/CVE-2024-24337/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/koha-community/koha","events":[{"introduced":"0"},{"last_affected":"f659a4d143905a852ed33dd118fa3f979750b50d"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"23.05.05"}]}}],"versions":["R_1-2-2RC4","R_1-3-0","R_1-3-1","R_1-3-2","R_1-3-3","R_1-9-0","R_1-9-1","R_1-9-2","R_1-9-3","R_2-0-0RC1","R_2-0-0pre1","R_2-0-0pre2","R_2-0-0pre3","R_2-0-0pre4","R_2-0-0pre5","R_2-1","R_2-4","v16.05.00","v16.05.00-beta","v16.11.00","v17.05.00","v17.11.00","v18.05.00","v18.05.00-rc1","v18.11.00","v19.05.00","v19.11.00","v20.05.00","v20.11.00","v21.05.00","v21.11.00","v22.05.00","v22.11.00","v23.05.00","v23.05.01","v23.05.02","v23.05.03","v23.05.04","v23.05.05","v3.00.00","v3.00.00-alpha","v3.00.00-beta","v3.00.00-beta2","v3.00.00-stableRC1","v3.02.00-alpha","v3.02.00-alpha2","v3.02.00-beta","v3.04.00","v3.08.00","v3.12.00-alpha","v3.12.00-alpha2","v3.12.00-beta1","v3.14.00-alpha1","v3.14.00-alpha2","v3.14.00-beta","v3.16.00","v3.16.00-beta","v3.16.00-rc","v3.18.00","v3.18.00-beta","v3.20.00","v3.20.00-beta","v3.22.00","v3.22.00-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24337.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}