{"id":"CVE-2026-70373","summary":"Koha - SQL Injection in reports/issues_stats.pl","details":"Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding.","modified":"2026-08-28T11:30:49.819949715Z","published":"2026-08-04T13:00:15.197Z","database_specific":{"cna_assigner":"TuranSec","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70373.json","unresolved_ranges":[{"extracted_events":[{"introduced":"25.05.00"},{"last_affected":"25.05.12"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://koha-community.org/"},{"type":"ADVISORY","url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42735"},{"type":"ADVISORY","url":"https://download.koha-community.org/koha-25.05.12.tar.gz"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70373.json"},{"type":"ADVISORY","url":"https://koha-community.org/koha-25-05-12-released/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70373"},{"type":"PACKAGE","url":"https://gitlab.com/koha-community/Koha"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/koha-community/Koha","events":[{"introduced":"0"},{"last_affected":"926655c0a86da8f2255bfbaa0983a7b120a83bef"},{"introduced":"3f2987eb19f7ac1987591d8e9b01961c39405b39"},{"last_affected":"ed96c9f656546909ce4c52b5eba2e74ab6e3b7e6"},{"introduced":"e4bb3afa5bc1a9951438c1963b12a27b5d16980c"},{"last_affected":"dacce7d3fc15860d26d06444c1f5c9a2d0d6a4a9"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"24.11.17"},{"introduced":"25.11.00"},{"last_affected":"25.11.06"},{"introduced":"26.05.00"},{"last_affected":"26.05.01"}]}}],"versions":["v25.11.06-1","v24.11.17-1","v26.05.01-1","v26.05.01","v24.11.16-2","v25.11.05-1","v26.05.00","v25.11.04-1","v24.11.14-1","v25.11.03-2","v25.11.03-1","v25.11.02-1","v24.11.13-1","v24.11.12-1","v25.11.01-2","v25.11.01-1","v25.11.00-2","v25.11.00-1","v24.11.11-2","v25.11.00","v24.11.11-1","v24.11.10-2","v24.11.09-1","v24.11.08-3","v24.11.08-2","v24.11.08-1","v24.11.07-1","v24.11.06-1","v24.11.05-1","v24.11.04-1","v24.11.03-3","v24.11.03-2","v24.11.02-1","v24.11.01","v24.11.00","v24.05.00","v23.11.00","v23.05.00","v22.11.00","v22.05.00","v21.11.00","v21.05.00","v20.11.00","v20.05.00","v19.11.00","v19.05.00","v18.11.00","v18.05.00","v18.05.00-rc1","v17.11.00","v17.05.00","v16.11.00","v16.05.00","v16.05.00-beta","v3.22.00","v3.22.00-beta","v3.20.00","v3.20.00-beta","v3.18.00","v3.18.00-beta","v3.16.00","v3.16.00-rc","v3.16.00-beta","v3.14.00-beta","v3.14.00-alpha2","v3.14.00-alpha1","v3.12.00-beta1","v3.12.00-alpha2","v3.12.00-alpha","v3.08.00","v3.04.00","v3.02.00-beta","v3.02.00-alpha2","v3.02.00-alpha","v3.00.00","v3.00.00-stableRC1","v3.00.00-beta2","v3.00.00-beta","v3.00.00-alpha","R_2-4","R_2-1","R_2-0-0RC1","R_2-0-0pre5","R_2-0-0pre4","R_2-0-0pre3","R_2-0-0pre2","R_2-0-0pre1","R_1-9-3","R_1-9-2","R_1-9-1","R_1-9-0","R_1-3-3","R_1-3-2","R_1-3-1","R_1-3-0","R_1-2-2RC4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70373.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}