Vulnerability Description
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=38829
- https://koha-community.org/koha-24-11-02-released/
FAQ
What is CVE-2025-22954?
CVE-2025-22954 is a vulnerability with a CVSS score of 10.0 (CRITICAL). GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
How severe is CVE-2025-22954?
CVE-2025-22954 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-22954?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.