CVE-2026-72609 | Koha Community up to 24.11.17/25.05.12/25.11.06/26.05.01 SQL Query Construction acqui/parcels.pl GetInvoices orderby sql injection
A vulnerability, which was classified as critical, has been found in Koha Community Koha up to 24.11.17/25.05.12/25.11.06/26.05.01. Affected by this issue is the function C4::Acquisition::GetInvoices of the file acqui/parcels.pl of the component SQL Query Construction. This manipulation of the argument orderby causes sql injection.
This vulnerability is handled as CVE-2026-72609. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More