Impact
The vulnerability is caused by the use of an unsafe eval function in Koha’s web service. Unvalidated user‑supplied strings are passed directly to eval, enabling code injection. An attacker who can authenticate to the Koha instance can submit a crafted request that is executed under the service account, giving the attacker full control over that account’s privileges on the host.
Affected Systems
Koha installations running the vulnerable web service on TCP port 8081 are affected. The advisory does not enumerate specific versions, so any Koha instance that has not applied the vendor’s fix should be considered potentially vulnerable, regardless of the date of the installation.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity. The EPSS score of less than 1% indicates a low probability that the vulnerability is being actively exploited in the wild, and the advisory is not listed in the CISA KEV catalog. Nevertheless, because authentication is required, a threat actor needs valid Koha credentials to use the flaw. Once authenticated, a simple carefully crafted payload sent over port 8081 can invoke eval and execute arbitrary code in the context of the service account, which could be used to pivot to the underlying system or exfiltrate data.
OpenCVE Enrichment