Impact
Ankaref Innovation and Technology Inc. LIBRID/LIBREF suffers from an improper neutralization of input during web page generation, resulting in a stored cross‑site scripting (XSS) vulnerability. An attacker who can inject script code into the management panel could have the payload executed in the browsers of other users who view the affected pages, potentially allowing theft of session cookies, credentials, or other sensitive data. This weakness is classified as CWE‑79 and delivers a moderate severity impact (CVSS 5.4).
Affected Systems
All installations of Ankaref’s LIBRID/LIBREF from version 2.01.0.2183 through 10092026 are affected. Administrators should verify the exact version deployed in their environment to determine exposure.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact, and no EPSS data is available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have sufficient privileges to inject content into the management panel—likely via authenticated access or a non‑restricted input field. Once injected, the script will persist and run for any user who views the affected content, providing broad availability and potential confidentiality impact. The lack of a publicly disclosed patch or workaround means that mitigation must rely on procedural controls and application hardening.
OpenCVE Enrichment