CVE-2024-24337

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/02/2024
Last modified:
29/09/2025

Description

CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* 23.05.05 (including)