Impact
Ankaref Innovation and Technology Inc. LIBRID/LIBREF contains a stored cross‑site scripting flaw. The application fails to neutralize user‑supplied content inserted into web pages, allowing an attacker to store arbitrary JavaScript that will execute whenever a user views the affected page. The vulnerability is limited to the presentation layer and does not directly alter the underlying database or system state.
Affected Systems
LIBRID/LIBREF versions from 2.01.0.2183 through 10092026 are affected. No other products or versions are listed in the advisory, and the vendor has not yet released a patch or a formal response.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity. Because no EPSS score is available and the issue is not listed in CISA KEV, the exploitation likelihood is unclear. Exploitation requires an attacker to supply malicious input that the application stores; the stored payload is subsequently served and executed by unsuspecting users’ browsers. Mitigation requires server‑side input validation or vendor‑issued fixes.
OpenCVE Enrichment