CVE-2015-4639: Koha
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.
Affected products
- Koha Koha: version 3.14.00 only; version 3.14.01 only; version 3.14.02 only; version 3.14.03 only; version 3.14.04 only; version 3.14.05 only; …
Published 2017-07-21. Last modified 2026-06-17.