oss-sec mailing list archives

CVE request: XSS issues in Koha


From: Chris Cormack <chris () bigballofwax co nz>
Date: Sat, 27 Dec 2014 16:30:05 +1300

Hi All

As a current release maintainer for Koha I would like to request a CVE
number for an XSS vulnerability that has been address by Koha releases
3.16.6 and 3.18.2

The bug fixed is
http://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=13425
There is an xss vulnerability in 3.16, 3.18 and master in the opac and
intranet facets

Thank you

Chris

Current thread: