← back
CVE-2015-4632

CVE-2015-4632

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 52%
from disclosure to weapon0 days
Published on NVDOct 18
1st PoCJun 26
exploitation probability
52%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.