{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-14T18:46:25.457","vulnerabilities":[{"cve":{"id":"CVE-2018-25101","sourceIdentifier":"cna@vuldb.com","published":"2024-04-22T02:15:07.547","lastModified":"2024-11-21T04:03:33.950","vulnStatus":"Awaiting Analysis","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability, which was classified as problematic, has been found in l2c2technologies Koha up to 20180108. This issue affects some unknown processing of the file \/cgi-bin\/koha\/opac-MARCdetail.pl. The manipulation of the argument biblionumber with the input 2\"><TEST> leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is 950fc8e101886821879066b33e389a47fb0a9782. It is recommended to upgrade the affected component. The identifier VDB-261677 was assigned to this vulnerability."},{"lang":"es","value":"Una vulnerabilidad, clasificada como problemática, ha sido encontrada en l2c2technologies Koha hasta 20180108. Este problema afecta a un procesamiento desconocido del archivo \/cgi-bin\/koha\/opac-MARCdetail.pl. La manipulación del argumento biblionumber con la entrada 2\"&gt; conduce a un cross site scripting. El ataque puede ser iniciado de forma remota. El identificador del parche es 950fc8e101886821879066b33e389a47fb0a9782. Se recomienda actualizar el componente afectado. El identificador VDB-261677 fue asignado a esta vulnerabilidad."}],"metrics":{"cvssMetricV31":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:U\/C:N\/I:L\/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":1.4}],"cvssMetricV2":[{"source":"cna@vuldb.com","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N\/AC:L\/Au:S\/C:N\/I:P\/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"cna@vuldb.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"references":[{"url":"https:\/\/github.com\/l2c2technologies\/Koha\/commit\/950fc8e101886821879066b33e389a47fb0a9782","source":"cna@vuldb.com"},{"url":"https:\/\/vuldb.com\/?ctiid.261677","source":"cna@vuldb.com"},{"url":"https:\/\/vuldb.com\/?id.261677","source":"cna@vuldb.com"},{"url":"https:\/\/github.com\/l2c2technologies\/Koha\/commit\/950fc8e101886821879066b33e389a47fb0a9782","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https:\/\/vuldb.com\/?ctiid.261677","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https:\/\/vuldb.com\/?id.261677","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}