CVE-2014-1923: Koha
High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.
Multiple directory traversal vulnerabilities in the (1) staff interface help editor (edithelp.pl) or (2) member-picupload.pl in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allow remote attackers to write to arbitrary files via unspecified vectors.
Affected products
- Koha Koha: before 3.08.23 (fixed in 3.08.23); from 3.10.00, before 3.10.13 (fixed in 3.10.13); from 3.12.00, before 3.12.10 (fixed in 3.12.10); from 3.14.00, before 3.14.03 (fixed in 3.14.03)
Published 2020-01-24. Last modified 2026-06-17.