Vulnerability Disclosures made from MaTRIS Group acknowledged at CVE MITRE: CVE 2015-4631, CVE 2015-4632, CVE 2015-4633
Some of the vulnerabilities found in the Koha Library software in the past from the combinatorial security testing team of SBA Research, now part of the MaTRIS group, have been officially acknowledged in the CVE-MITRE database.More details can be found below, below:
CVE-2015-4631 (Multiple cross-site scripting (XSS in Koha library)
Full vulnerability disclosure at CVE-MITRE database: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4631
CVE-2015-4632 (Multiple directory traversal vulnerabilities at Koha library)
Full vulnerability disclosure at CVE-MITRE database: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4632
CVE-2015-4633 (Multiple SQL injection vulnerabilities in Koha library)
Full vulnerability disclosure at CVE-MITRE database: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4633