Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-10
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Stored cross-site scripting in the management panel allowing malicious scripts to persist and execute in users' browsers
Action: Mitigate
AI Analysis

Impact

Ankaref Innovation and Technology Inc. LIBRID/LIBREF suffers from an improper neutralization of input during web page generation, resulting in a stored cross‑site scripting (XSS) vulnerability. An attacker who can inject script code into the management panel could have the payload executed in the browsers of other users who view the affected pages, potentially allowing theft of session cookies, credentials, or other sensitive data. This weakness is classified as CWE‑79 and delivers a moderate severity impact (CVSS 5.4).

Affected Systems

All installations of Ankaref’s LIBRID/LIBREF from version 2.01.0.2183 through 10092026 are affected. Administrators should verify the exact version deployed in their environment to determine exposure.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact, and no EPSS data is available. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have sufficient privileges to inject content into the management panel—likely via authenticated access or a non‑restricted input field. Once injected, the script will persist and run for any user who views the affected content, providing broad availability and potential confidentiality impact. The lack of a publicly disclosed patch or workaround means that mitigation must rely on procedural controls and application hardening.

Generated by OpenCVE AI on September 10, 2026 at 14:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Perform an inventory of all LIBRID/LIBREF installations and confirm their version numbers; if a non‑vulnerable version is available, plan an immediate upgrade.
  • Implement strict input validation and output encoding for all fields in the management panel to neutralize script payloads; applying a content security policy that disallows inline scripts can serve as an interim protection.
  • Restrict access to the management panel using least‑privilege authentication, monitoring login attempts, and ensuring that only trusted administrators can input data that could be stored and later rendered.

Generated by OpenCVE AI on September 10, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-10T17:07:38.142Z

Reserved: 2026-06-19T06:27:18.042Z

Link: CVE-2026-12683

cve-icon Vulnrichment

Updated: 2026-09-10T17:07:34.702Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:16:59.963

Modified: 2026-09-10T17:17:01.757

Link: CVE-2026-12683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T14:45:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')