CVE-2025-22954 | Koha up to 21.11 lateissues-export.pl supplierid sql injection
A vulnerability was found in Koha up to 21.11. It has been classified as critical. Affected is an unknown function of the file /serials/lateissues-export.pl. The manipulation of the argument supplierid leads to sql injection.
This vulnerability is traded as CVE-2025-22954. It is possible to launch the attack remotely. There is no exploit available.