{"id":"CVE-2026-6428","summary":"Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter","details":"SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/.","modified":"2026-08-12T03:51:16.544797707Z","published":"2026-06-13T16:34:10.326Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"22.11.38"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"TuranSec","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6428.json"},"references":[{"type":"WEB","url":"https://koha-community.org/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6428.json"},{"type":"ADVISORY","url":"https://koha-community.org/security-releases/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6428"},{"type":"REPORT","url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42361"},{"type":"FIX","url":"https://bugs.koha-community.org/bugzilla3/attachment.cgi?id=199539"},{"type":"PACKAGE","url":"https://gitlab.com/koha-community/Koha"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/koha-community/Koha","events":[{"introduced":"dd76c6bcdc4432d7f1ff900873b09116dc258f44"},{"last_affected":"3f0d2d4443e467a64d929a62d6effeb14a36bf9c"},{"introduced":"b16e2059a94cf8f803c5687460e73ccf6c85a5f0"},{"last_affected":"76e3b6ec9208bd73183df94f856d027b0bbe9df8"},{"introduced":"0"},{"last_affected":"1dbc309e9fead73bc11070ebe5da2c1dbe1f1489"},{"introduced":"3f2987eb19f7ac1987591d8e9b01961c39405b39"},{"last_affected":"278eb6a8c928fe94f5ed2bbf3b01111722a3ffc8"},{"introduced":"e4bb3afa5bc1a9951438c1963b12a27b5d16980c"},{"last_affected":"dacce7d3fc15860d26d06444c1f5c9a2d0d6a4a9"}],"database_specific":{"extracted_events":[{"introduced":"23.05.00"},{"last_affected":"23.11.15"},{"introduced":"24.05.00"},{"last_affected":"24.11.16"},{"introduced":"25.05.00"},{"last_affected":"25.05.11"},{"introduced":"25.11.00"},{"last_affected":"25.11.05"},{"introduced":"26.05.00"},{"last_affected":"26.05.01"}],"source":"AFFECTED_FIELD"}}],"versions":["v26.05.01-1","v26.05.01","v24.11.16-2","v25.11.05-1","v25.05.11-1","v26.05.00","v25.11.04-1","v25.05.10-1","v24.11.14-1","v25.05.09-4","v25.05.09-3","v25.05.09-2","v25.11.03-2","v25.11.03-1","v25.05.08-3","v25.11.02-1","v25.05.08-2","v24.11.13-1","v24.11.12-1","v25.05.07-1","v25.11.01-2","v25.11.01-1","v25.11.00-2","v25.11.00-1","v25.05.06-2","v24.11.11-2","v25.11.00","v24.11.11-1","v25.05.05-2","v25.05.05-1","v24.11.10-2","v25.05.04-1","v24.11.09-1","v24.11.08-3","v25.05.03-1","v24.11.08-2","v24.11.08-1","v25.05.02-2","v25.05.02-1","v24.11.07-1","v25.05.01-1","v24.11.06-1","v24.11.05-1","v25.05.00-1","v23.11.15-1","v24.11.04-1","v23.11.14-1","v23.11.13-1","v24.11.03-3","v24.11.03-2","v24.11.02-1","v23.11.12-1","v23.11.11","v24.11.01","v24.11.00","v23.11.10","v23.11.09","v23.11.08-1","v23.11.08","v23.11.07","v23.11.06-1","v23.11.06","v24.05.00","v23.11.05","v23.11.04-4","v23.11.04","v23.11.03","v23.11.02","v23.11.01","v23.11.00","v23.05.00"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6428.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/AU:Y/V:C/U:Amber"}]}