Impact
Koha versions prior to 26.05.02, 25.11.07, and 25.05.13 store unsanitized input from the purchase suggestion handler, enabling an authenticated staff user to inject arbitrary HTML or JavaScript. When a staff member later views the suggestion list, the script executes in the user's browser, potentially allowing session hijacking, credential theft, or defacement of the interface. The flaw constitutes a stored XSS vulnerability.
Affected Systems
The affected products are the Koha Community software before releases 26.05.02, 25.11.07, and 25.05.13. All staff accounts with permissions to submit purchase suggestions can exploit the vulnerability.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS score is not available, and the flaw is not listed in CISA KEV. Exploitation requires authentication as a staff user with access to the purchase suggestion feature; there is no network‑level attack vector. Once the attacker has credentials, the vulnerability can be abused to run scripts in the browser of any other staff member who views the suggestion list.
OpenCVE Enrichment