[Bug 42735] [CVE-2026-70373] SQL Injection in reports/issues_stats.pl via PeriodTypeSel / PeriodDaySel / PeriodMonthSel / Filter parameters (unvalidated string context, no placeholders)
https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42735 David Cook <dcook@prosentient.com.au> changed: What |Removed |Added ---------------------------------------------------------------------------- Summary|SQL Injection in |[CVE-2026-70373] SQL |reports/issues_stats.pl via |Injection in |PeriodTypeSel / |reports/issues_stats.pl via |PeriodDaySel / |PeriodTypeSel / |PeriodMonthSel / Filter |PeriodDaySel / |parameters (unvalidated |PeriodMonthSel / Filter |string context, no |parameters (unvalidated |placeholders) |string context, no | |placeholders) -- You are receiving this mail because: You are watching all bug changes.
participants (1)
-
bugzilla-daemon@bugs.koha-community.org