Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-21759 | CSV Injection vulnerability in '/members/moremember.pl' and '/admin/aqbudgets.pl' endpoints in Koha Library Management System version 23.05.05 and earlier allows attackers to to inject DDE commands into csv exports via the 'Budget' and 'Patrons Member' components. |
Mon, 29 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Koha-community
Koha-community koha Library Software |
|
| CPEs | cpe:2.3:a:koha-community:koha_library_software:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Koha-community
Koha-community koha Library Software |
|
| Metrics |
cvssV3_1
|
ssvc
|
Mon, 29 Sep 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Koha
Koha koha |
|
| CPEs | cpe:2.3:a:koha:koha:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Koha
Koha koha |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 26 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1236 | |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-29T14:22:32.206Z
Reserved: 2024-01-25T00:00:00.000Z
Link: CVE-2024-24337
Updated: 2024-08-01T23:19:52.558Z
Status : Modified
Published: 2024-02-12T22:15:08.430
Modified: 2025-09-29T15:16:05.927
Link: CVE-2024-24337
No data.
OpenCVE Enrichment
No data.
EUVD