CVE-2026-31844 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: March 11, 2026
Koha - SQL Injection
Overview
Koha contains an authenticated SQL injection caused by improper sanitization of the "displayby" parameter in /cgi-bin/koha/suggestion/suggestion.pl, letting low-privileged staff users execute arbitrary SQL queries and retrieve sensitive data.
Severity & Score
Impact
Low-privileged staff users can execute arbitrary SQL queries, leading to sensitive database information disclosure.
Mitigation
Update to the latest version of Koha.
References
Social Media Activity(1 post)
š CVE-2026-31844 - High (8.8) An authenticated SQL Injection vulnerability (CWE-89) exists in the Koha staff interface in the /cgi-bin/koha/suggestion/suggestion.pl endpoint due to improper validation of the displayby parameter used by the GetDistinctValues functionality. A lo... š https://www.thehackerwire.com/vulnerability/CVE-2026-31844/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2026-31844
- Severity
- High
- CVSS Score
- 8.8
- Type
- sql_injection
- Status
- unconfirmed
- EPSS
- 4.0%
- Social Posts
- 1
CWE
- CWE-89
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H