CVE-2026-70371: CWE-89 SQL Injection in Koha Community Koha
Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are not validated against any whitelist and land verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY), and each Filter slot is concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments with no bound parameters.
AI Analysis
Technical Summary
Koha's reports/issues_avg_stats.pl script constructs dynamic SQL queries by concatenating user-supplied parameters (Line, Column, and Filter) directly into the query string without validation or use of bound parameters. The Line and Column parameters are used verbatim in SQL identifier positions such as SELECT DISTINCTROW, GROUP BY, and ORDER BY clauses, while Filter parameters are concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments. This improper handling leads to a SQL Injection vulnerability (CWE-89) that can be exploited to execute arbitrary SQL commands with the privileges of the application user.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker with limited privileges to execute arbitrary SQL queries on the Koha database. This can lead to unauthorized data disclosure, modification, or deletion, and potentially disrupt the availability of the affected system. The CVSS score of 8.8 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid exposing the vulnerable reports/issues_avg_stats.pl functionality to untrusted users and consider applying input validation or query parameterization as a temporary mitigation.
CVE-2026-70371: CWE-89 SQL Injection in Koha Community Koha
Description
Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are not validated against any whitelist and land verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY), and each Filter slot is concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments with no bound parameters.
CVSS v3.1
Score 8.8high
Affected software
Koha Community
Koha
pkg:github/koha-community/KohaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Koha's reports/issues_avg_stats.pl script constructs dynamic SQL queries by concatenating user-supplied parameters (Line, Column, and Filter) directly into the query string without validation or use of bound parameters. The Line and Column parameters are used verbatim in SQL identifier positions such as SELECT DISTINCTROW, GROUP BY, and ORDER BY clauses, while Filter parameters are concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments. This improper handling leads to a SQL Injection vulnerability (CWE-89) that can be exploited to execute arbitrary SQL commands with the privileges of the application user.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker with limited privileges to execute arbitrary SQL queries on the Koha database. This can lead to unauthorized data disclosure, modification, or deletion, and potentially disrupt the availability of the affected system. The CVSS score of 8.8 reflects high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid exposing the vulnerable reports/issues_avg_stats.pl functionality to untrusted users and consider applying input validation or query parameterization as a temporary mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-04T07:13:07.992Z
- State
- PUBLISHED
Threat ID: 6a71ec42bf8831d539e19d2f
Added to database: 08/04/2026, 13:42:26 UTC
Last enriched: 08/11/2026, 17:05:19 UTC
Last updated: 09/17/2026, 22:01:37 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.