CVE-2015-4639

EUVD-2015-4658
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Affected Products (NVD)
VendorProductVersion
kohakoha
3.14.00
kohakoha
3.14.00:alpha1
kohakoha
3.14.00:alpha2
kohakoha
3.14.00:beta
kohakoha
3.14.01
kohakoha
3.14.02
kohakoha
3.14.03
kohakoha
3.14.04
kohakoha
3.14.05
kohakoha
3.14.06
kohakoha
3.14.07
kohakoha
3.14.08
kohakoha
3.14.09
kohakoha
3.14.10
kohakoha
3.14.11
kohakoha
3.14.12
kohakoha
3.14.13
kohakoha
3.14.14
kohakoha
3.14.15
kohakoha
3.16.00
kohakoha
3.16.00:beta
kohakoha
3.16.00:pkg
kohakoha
3.16.00:rc
kohakoha
3.16.01
kohakoha
3.16.02
kohakoha
3.16.03
kohakoha
3.16.04
kohakoha
3.16.05
kohakoha
3.16.06
kohakoha
3.16.07
kohakoha
3.16.08
kohakoha
3.16.09
kohakoha
3.16.10
kohakoha
3.16.11
kohakoha
3.20.00
kohakoha
3.20.00:beta
𝑥
= Vulnerable software versions