Impact
The vulnerability stems from missing authentication on a critical function within the Library Reservation System. An attacker can manipulate input data to perform reservation operations without proper verification, potentially creating, modifying, or deleting reservations without the user’s knowledge. This weakness could compromise confidentiality and integrity of reservation data, and disrupt normal library operations.
Affected Systems
The flaw is present in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc.’s Library Reservation System, affecting all releases prior to version 22.2.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability is considered moderate in severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting limited public exploitation. The likely attack vector is remote, via the system’s web or API interface, where unauthenticated requests can invoke the vulnerable function. Typical prerequisites include network connectivity to the system and the ability to craft requests to the reservation endpoint. An attacker would gain unauthorized control over reservation data without the need for additional credentials.
OpenCVE Enrichment