Impact
Ankaref Innovation and Technology Inc.’s LIBRID/LIBREF contains a stored XSS vulnerability caused by improper neutralization of input when generating web pages. The flaw allows malicious scripts to be persisted and subsequently executed in the browsers of users who view the affected content, potentially enabling unauthorized actions or data exfiltration. The weakness is classified under CWE‑79.
Affected Systems
All installations of Ankaref’s LIBRID/LIBREF from version 2.01.0.2183 up to, but not including, 18.9.26.2319 are vulnerable. Users and administrators should verify the exact version deployed to assess exposure.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact. The EPSS score is below 1 %, reflecting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires injection of script code into a field that is rendered by the management panel. Once stored, the payload will be delivered to any user who accesses the affected page, providing a persistent risk until the system is upgraded.
OpenCVE Enrichment