CVE-2022-0495 CRITICAL

CVE-2022-0495: SQL Injection in KOHA

Vendor Parantez Teknoloji
Product Parantez Teknoloji
Weakness CWE-89 · SQLi
Published September 21, 2022
Last update May 20, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticated SQL Injection vulnerability. This has been fixed in the version 19.05.03.01.

Key dates

02Disclosure timeline

September 21, 2022 CVE published
May 20, 2026 Record updated