Ad

CVE-2024-36058

CRITICAL CVSS 3.1: 9.8 EPSS 0.11%
Updated Apr 09, 2026
The Send
Parameter Value
CVSS 9.8 (CRITICAL)
Affected Versions before 23.05.10
Type CWE-89 (SQL Injection)
Vendor The Send
Public PoC No

The Send Basket functionality in Koha Library before 23.05.10 is susceptible to Time-Based SQL Injection because it fails to sanitize the POST parameter bib_list in /cgi-bin/koha/opac-sendbasket.pl, allowing library users to read arbitrary data from the database.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)