cvedb.io
CVE-2015-4630
HIGH · CVSS 8
EPSS exploitation probability: 0%
Published 2018-10-18T21:29:00.270 · Last modified 2026-06-17T00:27:37.837

Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.

Affected products

koha — koha

Does this affect you?

Add your gear to cvedb and we'll alert you only when koha ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.