An issue in Koha v.25.11 and before allows a remote attacker to execute arbitrary code via the Z39.50 configuration module