
Authenticated SQL Injection Vulnerability in Koha Puts Database at Risk
General
📌 A vulnerability identified as CVE-2026-31844 was published on March 11, 2026, affecting Koha, an open-source library management system. The flaw is an authenticated SQL injection (SQLi) vulnerability located in the staff interface, specifically within the suggestion management module (suggestion.pl). The issue stems from improper handling of the displayby parameter, allowing authenticated staff users to exploit it. The vulnerability exposes the database to potential compromise through the staff interface. No additional technical details or exploitation impacts were specified beyond the risk to database integrity.