CVE-2023-44962: Koha-Community Koha Library Software

Medium severity, CVSS 5.3. EPSS: 1.2% chance of exploitation in the next 30 days.

File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.

Affected products

Published 2023-10-11. Last modified 2026-06-17.