What is CVE-2026-70370?
CVE-2026-70370 in Koha involves an SQL injection vulnerability in the `reports/catalogue_stats.pl` script, where the `calculate` subroutine interpolates user-supplied `Line` and `Column` parameters directly into SQL identifier positions without whitelist validation. This allows an authenticated attacker to execute arbitrary SQL queries on the database. Users should immediately apply patches or enhance input validation.
Azərbaycanca: Koha kitabxana sistemində aşkar edilən CVE-2026-70370 zəifliyi `reports/catalogue_stats.pl` faylındakı `calculate` altproqramında istifadəçi tərəfindən idarə olunan `Line` və `Column` parametrlərinin SQL sorğusuna birbaşa daxil edilməsi ilə bağlıdır. Bu, autentifikasiya olunmuş istifadəçiyə verilənlər bazasında özbaşına sorğular icra etməyə imkan verir. Koha istifadəçiləri dərhal yamaq tətbiq etməli və ya giriş doğrulama mexanizmlərini gücləndirməlidirlər.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Koha
FAQ2
In which component of the Koha library system was CVE-2026-70370 discovered?
The vulnerability was discovered in the `calculate` subroutine within the `reports/catalogue_stats.pl` script.
Does exploiting CVE-2026-70370 require authentication?
Yes, this vulnerability allows an authenticated user to execute arbitrary SQL queries on the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.