
CVE-2024-36057 Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirn… https://www.cve.org/CVERecord?id=CVE-2024-36057
Post summary
The text announces CVE-2024-36057, a remote code execution flaw in Koha Library caused by unsanitized filenames during unzipping, without mentioning PoC, patch, or active exploitation.

