Impact
The vulnerability arises because Ankaref Innovation and Technology Inc. LIBRID/LIBREF fails to neutralize user‑supplied input when generating web pages. This improper input handling lets an attacker store malicious JavaScript that will run whenever a user views an affected page. The flaw is a stored cross‑site scripting (XSS) vulnerability. It impacts the presentation layer and does not alter the underlying database or system state.
Affected Systems
Ankaref Innovation and Technology Inc. LIBRID/LIBREF versions from 2.01.0.2183 up to, but not including, 18.9.26.2319 are affected. No other products or versions are affected according to the advisory, and a vendor patch has not yet been released.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity. The EPSS score of 0.0016 indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to supply malicious input that the application stores; the stored payload is subsequently served and executed by unsuspecting users’ browsers. Mitigation requires server‑side input validation or vendor‑issued fixes.
OpenCVE Enrichment