← back
CVE-2025-22954criticalCWE-89

CVE-2025-22954

53Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 10epss 25%
from disclosure to weapon7 days
Published on NVDMar 12
1st PoC+7d
exploitation probability
25%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl via the supplierid or serialid parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Koha · Koha
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.