CVE-2026-50765 PUBLISHED

Assigner: mitre
Reserved: 07.06.2026 Published: 26.06.2026 Updated: 26.06.2026

Cross-Site Scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System through 25.11 allows an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field)

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text