Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Ankaref Innovation and Technology Inc. LIBRID/LIBREF contains a stored cross‑site scripting flaw. The application fails to neutralize user‑supplied content inserted into web pages, allowing an attacker to store arbitrary JavaScript that will execute whenever a user views the affected page. The vulnerability is limited to the presentation layer and does not directly alter the underlying database or system state.

Affected Systems

LIBRID/LIBREF versions from 2.01.0.2183 through 10092026 are affected. No other products or versions are listed in the advisory, and the vendor has not yet released a patch or a formal response.

Risk and Exploitability

The CVSS score of 5.4 reflects moderate severity. Because no EPSS score is available and the issue is not listed in CISA KEV, the exploitation likelihood is unclear. Exploitation requires an attacker to supply malicious input that the application stores; the stored payload is subsequently served and executed by unsuspecting users’ browsers. Mitigation requires server‑side input validation or vendor‑issued fixes.

Generated by OpenCVE AI on September 10, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest LIBRID/LIBREF release once the vendor issues a fix for the stored XSS flaw
  • Implement input validation or sanitization that rejects or encodes JavaScript and other executable content before storage
  • Apply a Content Security Policy that restricts inline script execution and disallows unsafe-eval to mitigate the impact of any residual XSS content

Generated by OpenCVE AI on September 10, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Stored XSS in Ankaref's LIBRID/LIBREF
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-10T17:00:13.850Z

Reserved: 2026-06-19T06:20:37.965Z

Link: CVE-2026-12682

cve-icon Vulnrichment

Updated: 2026-09-10T16:59:45.708Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:16:59.827

Modified: 2026-09-10T17:17:01.640

Link: CVE-2026-12682

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')