CVE Vulnerabilities

CVE-2024-24337

Published: Feb 12, 2024 | Modified: Feb 12, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

CSV Injection vulnerability in /members/moremember.pl and /admin/aqbudgets.pl endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the Budget and Patrons Member components.

References