Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Koha | Koha | 3.14.00 (including) | 3.14.00 (including) |
Koha | Koha | 3.14.00-alpha1 (including) | 3.14.00-alpha1 (including) |
Koha | Koha | 3.14.00-alpha2 (including) | 3.14.00-alpha2 (including) |
Koha | Koha | 3.14.00-beta (including) | 3.14.00-beta (including) |
Koha | Koha | 3.14.01 (including) | 3.14.01 (including) |
Koha | Koha | 3.14.02 (including) | 3.14.02 (including) |
Koha | Koha | 3.14.03 (including) | 3.14.03 (including) |
Koha | Koha | 3.14.04 (including) | 3.14.04 (including) |
Koha | Koha | 3.14.05 (including) | 3.14.05 (including) |
Koha | Koha | 3.14.06 (including) | 3.14.06 (including) |
Koha | Koha | 3.14.07 (including) | 3.14.07 (including) |
Koha | Koha | 3.14.08 (including) | 3.14.08 (including) |
Koha | Koha | 3.14.09 (including) | 3.14.09 (including) |
Koha | Koha | 3.14.10 (including) | 3.14.10 (including) |
Koha | Koha | 3.14.11 (including) | 3.14.11 (including) |
Koha | Koha | 3.14.12 (including) | 3.14.12 (including) |
Koha | Koha | 3.14.13 (including) | 3.14.13 (including) |
Koha | Koha | 3.14.14 (including) | 3.14.14 (including) |
Koha | Koha | 3.14.15 (including) | 3.14.15 (including) |
Koha | Koha | 3.16.00 (including) | 3.16.00 (including) |
Koha | Koha | 3.16.00-beta (including) | 3.16.00-beta (including) |
Koha | Koha | 3.16.00-pkg (including) | 3.16.00-pkg (including) |
Koha | Koha | 3.16.00-rc (including) | 3.16.00-rc (including) |
Koha | Koha | 3.16.01 (including) | 3.16.01 (including) |
Koha | Koha | 3.16.02 (including) | 3.16.02 (including) |
Koha | Koha | 3.16.03 (including) | 3.16.03 (including) |
Koha | Koha | 3.16.04 (including) | 3.16.04 (including) |
Koha | Koha | 3.16.05 (including) | 3.16.05 (including) |
Koha | Koha | 3.16.06 (including) | 3.16.06 (including) |
Koha | Koha | 3.16.07 (including) | 3.16.07 (including) |
Koha | Koha | 3.16.08 (including) | 3.16.08 (including) |
Koha | Koha | 3.16.09 (including) | 3.16.09 (including) |
Koha | Koha | 3.16.10 (including) | 3.16.10 (including) |
Koha | Koha | 3.16.11 (including) | 3.16.11 (including) |
Koha | Koha | 3.20.00 (including) | 3.20.00 (including) |
Koha | Koha | 3.20.00-beta (including) | 3.20.00-beta (including) |