{"id":"CVE-2024-36058","details":"The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.","modified":"2026-08-12T03:51:37.602609980Z","published":"2026-04-07T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36058.json","unresolved_ranges":[{"extracted_events":[{"fixed":"23.05.10"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://github.com/hacklantic/Research/tree/main/CVE-2024-36058"},{"type":"WEB","url":"https://gitlab.com/koha-community/Koha/-/blob/23.05.x/misc/release_notes/release_notes_23_05_10.md"},{"type":"WEB","url":"https://gitlab.com/koha-community/Koha/-/blob/23.05.x/misc/release_notes/release_notes_23_05_11.md"},{"type":"WEB","url":"https://koha-community.org/koha-22-05-22-released/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36058.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-36058"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/koha-community/Koha","events":[{"introduced":"0"},{"fixed":"37a2f404b4bfadc0a37fb2bf6788797f2574bc69"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"23.05.10"}]}}],"versions":["v23.05.09-01","v23.05.09","v23.05.08","v23.05.07","v23.05.06","v23.05.05","v23.05.04","v23.05.03","v23.05.02","v23.05.01","v23.05.00","v22.11.00","v22.05.00","v21.11.00","v21.05.00","v20.11.00","v20.05.00","v19.11.00","v19.05.00","v18.11.00","v18.05.00","v18.05.00-rc1","v17.11.00","v17.05.00","v16.11.00","v16.05.00","v16.05.00-beta","v3.22.00","v3.22.00-beta","v3.20.00","v3.20.00-beta","v3.18.00","v3.18.00-beta","v3.16.00","v3.16.00-rc","v3.16.00-beta","v3.14.00-beta","v3.14.00-alpha2","v3.14.00-alpha1","v3.12.00-beta1","v3.12.00-alpha2","v3.12.00-alpha","v3.08.00","v3.04.00","v3.02.00-beta","v3.02.00-alpha2","v3.02.00-alpha","v3.00.00","v3.00.00-stableRC1","v3.00.00-beta2","v3.00.00-beta","v3.00.00-alpha","R_2-4","R_2-1","R_2-0-0RC1","R_2-0-0pre5","R_2-0-0pre4","R_2-0-0pre3","R_2-0-0pre2","R_2-0-0pre1","R_1-9-3","R_1-9-2","R_1-9-1","R_1-9-0","R_1-3-3","R_1-3-2","R_1-3-1","R_1-3-0","R_1-2-2RC4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-36058.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}