A vulnerability classified as problematic has been found in Koha Community Koha up to 24.11.16/25.05.11/25.11.5/26.05.0. Affected by this vulnerability is the function
calculate of the file reports/issues_stats.pl of the component Circulation Statistics Report. This manipulation of the argument PeriodTypeSel/PeriodDaySel/PeriodMonthSel causes sql injection.
This vulnerability is registered as CVE-2026-70373. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.