← Vulnerability feed

Vulnerability record · CVE-2015-4630 · published 18 October 2018

CVE-2015-4630: Koha cross-site request forgery vulnerability

Koha · Koha

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.

8.0 CVSS 3.0 High EPSS 3.0% · top 13.3% CWE-352 · Cross-site request forgery
8.0CVSS 3.0 base score, v2 6.0
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14423 ExploitIssue TrackingVendor Advisory
https://koha-community.org/koha-3-14-16-released/ ProductRelease NotesVendor Advisory
https://koha-community.org/security-release-koha-3-16-12/ ProductRelease NotesVendor Advisory
https://koha-community.org/security-release-koha-3-18-8/ ProductRelease NotesVendor Advisory
https://koha-community.org/security-release-koha-3-20-1/ ProductRelease NotesVendor Advisory
https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html ExploitThird Party AdvisoryVDB Entry
https://seclists.org/fulldisclosure/2015/Jun/80 ExploitMailing ListThird Party Advisory
https://www.exploit-db.com/exploits/37389/ Third Party AdvisoryVDB Entry
https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-t Third Party Advisory
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=14423 ExploitIssue TrackingVendor Advisory
https://koha-community.org/koha-3-14-16-released/ ProductRelease NotesVendor Advisory
https://koha-community.org/security-release-koha-3-16-12/ ProductRelease NotesVendor Advisory
https://koha-community.org/security-release-koha-3-18-8/ ProductRelease NotesVendor Advisory
https://koha-community.org/security-release-koha-3-20-1/ ProductRelease NotesVendor Advisory
https://packetstormsecurity.com/files/132458/Koha-ILS-3.20.x-CSRF-XSS-Traversal-SQL-Injection.html ExploitThird Party AdvisoryVDB Entry
https://seclists.org/fulldisclosure/2015/Jun/80 ExploitMailing ListThird Party Advisory
https://www.exploit-db.com/exploits/37389/ Third Party AdvisoryVDB Entry
https://www.sba-research.org/2015/06/24/researchers-of-sba-research-found-several-critical-security-vulnerabilities-in-t Third Party Advisory

Track CVE-2015-4630 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-1924Koha sql injection vulnerabilityThe MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and…EPSS 2.0%9.8CVE-2014-1925Koha sql injection vulnerabilitySQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10…EPSS 2.0%9.8CVE-2015-4633Koha sql injection vulnerabilityMultiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1…EPSS 6.1%9.6CVE-2024-28740Koha cross-site scripting vulnerabilityCross Site Scripting vulnerability in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via the additonal-contents.pl comp…EPSS 0.71%8.8CVE-2018-1000669Koha cross-site request forgery vulnerabilityKOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in…EPSS 0.48%8.8CVE-2015-4639Koha cross-site request forgery vulnerabilityCross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 …EPSS 0.62%8.7CVE-2026-31844Koha sql injection vulnerabilityAn authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due t…EPSS 0.57%8.0CVE-2024-24337Koha csv injection vulnerabilityCSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and ea…EPSS 0.81%

Source: NIST National Vulnerability Database (record CVE-2015-4630), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.