{"id":"CVE-2024-28739","details":"An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.","modified":"2026-04-10T05:11:32.223047Z","published":"2024-08-06T19:15:56.287Z","references":[{"type":"EVIDENCE","url":"https://febin0x4e4a.wordpress.com/2024/03/07/xss-to-one-click-rce-in-koha-ils/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/koha-community/koha","events":[{"introduced":"0"},{"last_affected":"dd76c6bcdc4432d7f1ff900873b09116dc258f44"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"23.05.00"}]}}],"versions":["R_1-2-2RC4","R_1-3-0","R_1-3-1","R_1-3-2","R_1-3-3","R_1-9-0","R_1-9-1","R_1-9-2","R_1-9-3","R_2-0-0RC1","R_2-0-0pre1","R_2-0-0pre2","R_2-0-0pre3","R_2-0-0pre4","R_2-0-0pre5","R_2-1","R_2-4","v16.05.00","v16.05.00-beta","v16.11.00","v17.05.00","v17.11.00","v18.05.00","v18.05.00-rc1","v18.11.00","v19.05.00","v19.11.00","v20.05.00","v20.11.00","v21.05.00","v21.11.00","v22.05.00","v22.11.00","v23.05.00","v3.00.00","v3.00.00-alpha","v3.00.00-beta","v3.00.00-beta2","v3.00.00-stableRC1","v3.02.00-alpha","v3.02.00-alpha2","v3.02.00-beta","v3.04.00","v3.08.00","v3.12.00-alpha","v3.12.00-alpha2","v3.12.00-beta1","v3.14.00-alpha1","v3.14.00-alpha2","v3.14.00-beta","v3.16.00","v3.16.00-beta","v3.16.00-rc","v3.18.00","v3.18.00-beta","v3.20.00","v3.20.00-beta","v3.22.00","v3.22.00-beta"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28739.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}