CVE-2022-0495

The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.
References
Link Resource
https://www.usom.gov.tr/bildirim/tr-22-0635 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:parantezteknoloji:koha_library_automation:*:*:*:*:*:*:*:*

History

17 Sep 2024, 01:15

Type Values Removed Values Added
Summary (en) The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01. (en) The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.

03 Sep 2023, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 9.4
Summary The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01. The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.

Information

Published : 2022-09-21 09:15

Updated : 2024-09-17 01:15


NVD link : CVE-2022-0495

Mitre link : CVE-2022-0495

CVE.ORG link : CVE-2022-0495


JSON object : View

Products Affected

parantezteknoloji

  • koha_library_automation
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')