CVE-2015-4639

Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
kohakoha
3.14.00
kohakoha
3.14.00:alpha1
kohakoha
3.14.00:alpha2
kohakoha
3.14.00:beta
kohakoha
3.14.01
kohakoha
3.14.02
kohakoha
3.14.03
kohakoha
3.14.04
kohakoha
3.14.05
kohakoha
3.14.06
kohakoha
3.14.07
kohakoha
3.14.08
kohakoha
3.14.09
kohakoha
3.14.10
kohakoha
3.14.11
kohakoha
3.14.12
kohakoha
3.14.13
kohakoha
3.14.14
kohakoha
3.14.15
kohakoha
3.16.00
kohakoha
3.16.00:beta
kohakoha
3.16.00:pkg
kohakoha
3.16.00:rc
kohakoha
3.16.01
kohakoha
3.16.02
kohakoha
3.16.03
kohakoha
3.16.04
kohakoha
3.16.05
kohakoha
3.16.06
kohakoha
3.16.07
kohakoha
3.16.08
kohakoha
3.16.09
kohakoha
3.16.10
kohakoha
3.16.11
kohakoha
3.20.00
kohakoha
3.20.00:beta
𝑥
= Vulnerable software versions