{"id":"CVE-2026-70372","summary":"Koha: SQL Injection in reports/bor_issues_top.pl","details":"Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized by a table-name prefix and is never whitelisted, landing verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY); Filter values are concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments, and the Limit parameter is appended raw to a LIMIT clause. An authenticated staff user holding the reports module permission can inject arbitrary SQL and read any table reachable by the Koha database user, including borrowers (password hashes, two-factor secrets, personal data), api_keys, and sessions.","modified":"2026-08-06T03:48:28.404950449Z","published":"2026-08-04T13:00:12.836Z","database_specific":{"cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70372.json","unresolved_ranges":[{"extracted_events":[{"introduced":"25.05.00"},{"fixed":"25.05.12"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"TuranSec"},"references":[{"type":"WEB","url":"https://download.koha-community.org/koha-25.05.12.tar.gz"},{"type":"WEB","url":"https://koha-community.org/"},{"type":"WEB","url":"https://koha-community.org/koha-25-05-12-released/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70372.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70372"},{"type":"REPORT","url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42369"},{"type":"PACKAGE","url":"https://gitlab.com/koha-community/Koha"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/koha-community/Koha","events":[{"introduced":"0"},{"fixed":"926655c0a86da8f2255bfbaa0983a7b120a83bef"},{"introduced":"3f2987eb19f7ac1987591d8e9b01961c39405b39"},{"fixed":"ed96c9f656546909ce4c52b5eba2e74ab6e3b7e6"},{"introduced":"e4bb3afa5bc1a9951438c1963b12a27b5d16980c"},{"fixed":"dacce7d3fc15860d26d06444c1f5c9a2d0d6a4a9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"24.11.17"},{"introduced":"25.11.00"},{"fixed":"25.11.06"},{"introduced":"26.05.00"},{"fixed":"26.05.01"}],"source":"AFFECTED_FIELD"}}],"versions":["v24.11.16-2","v25.11.05-1","v26.05.00","v25.11.04-1","v24.11.14-1","v25.11.03-2","v25.11.03-1","v25.11.02-1","v24.11.13-1","v24.11.12-1","v25.11.01-2","v25.11.01-1","v25.11.00-2","v25.11.00-1","v24.11.11-2","v25.11.00","v24.11.11-1","v24.11.10-2","v24.11.09-1","v24.11.08-3","v24.11.08-2","v24.11.08-1","v24.11.07-1","v24.11.06-1","v24.11.05-1","v24.11.04-1","v24.11.03-3","v24.11.03-2","v24.11.02-1","v24.11.01","v24.11.00","v24.05.00","v23.11.00","v23.05.00","v22.11.00","v22.05.00","v21.11.00","v21.05.00","v20.11.00","v20.05.00","v19.11.00","v19.05.00","v18.11.00","v18.05.00","v18.05.00-rc1","v17.11.00","v17.05.00","v16.11.00","v16.05.00","v16.05.00-beta","v3.22.00","v3.22.00-beta","v3.20.00","v3.20.00-beta","v3.18.00","v3.18.00-beta","v3.16.00","v3.16.00-rc","v3.16.00-beta","v3.14.00-beta","v3.14.00-alpha2","v3.14.00-alpha1","v3.12.00-beta1","v3.12.00-alpha2","v3.12.00-alpha","v3.08.00","v3.04.00","v3.02.00-beta","v3.02.00-alpha2","v3.02.00-alpha","v3.00.00","v3.00.00-stableRC1","v3.00.00-beta2","v3.00.00-beta","v3.00.00-alpha","R_2-4","R_2-1","R_2-0-0RC1","R_2-0-0pre5","R_2-0-0pre4","R_2-0-0pre3","R_2-0-0pre2","R_2-0-0pre1","R_1-9-3","R_1-9-2","R_1-9-1","R_1-9-0","R_1-3-3","R_1-3-2","R_1-3-1","R_1-3-0","R_1-2-2RC4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70372.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}