CVE-2025-22954
CRITICAL 10.0EPSS 25.6%
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS
- 25.55% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2025-03-12
- Updated
- 2025-03-18
Proof-of-concept exploits (1)
- RandomRobbieBF/CVE-2025-229541★ · 2025-03-19