Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.
Published: 2026-09-10
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Pending
AI Analysis

Impact

The vulnerability arises because Ankaref Innovation and Technology Inc. LIBRID/LIBREF fails to neutralize user‑supplied input when generating web pages. This improper input handling lets an attacker store malicious JavaScript that will run whenever a user views an affected page. The flaw is a stored cross‑site scripting (XSS) vulnerability. It impacts the presentation layer and does not alter the underlying database or system state.

Affected Systems

Ankaref Innovation and Technology Inc. LIBRID/LIBREF versions from 2.01.0.2183 up to, but not including, 18.9.26.2319 are affected. No other products or versions are affected according to the advisory, and a vendor patch has not yet been released.

Risk and Exploitability

The CVSS score of 5.4 reflects moderate severity. The EPSS score of 0.0016 indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to supply malicious input that the application stores; the stored payload is subsequently served and executed by unsuspecting users’ browsers. Mitigation requires server‑side input validation or vendor‑issued fixes.

Generated by OpenCVE AI on September 23, 2026 at 16:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest LIBRID/LIBREF release once the vendor issues a fix for the stored XSS flaw
  • Implement input validation or sanitization that rejects or encodes JavaScript and other executable content before storage
  • Apply a Content Security Policy that restricts inline script execution and disallows unsafe-eval to mitigate the impact of any residual XSS content

Generated by OpenCVE AI on September 23, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ankaref Innovation And Technology Inc.
Ankaref Innovation And Technology Inc. librid/libref
Vendors & Products Ankaref Innovation And Technology Inc.
Ankaref Innovation And Technology Inc. librid/libref

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Stored XSS in Ankaref's LIBRID/LIBREF
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ankaref Innovation And Technology Inc. Librid/libref
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-23T08:20:26.966Z

Reserved: 2026-06-19T06:20:37.965Z

Link: CVE-2026-12682

cve-icon Vulnrichment

Updated: 2026-09-10T16:59:45.708Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:16:59.827

Modified: 2026-09-23T09:17:06.227

Link: CVE-2026-12682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:30:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')