Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.
Published: 2026-09-10
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting in the management panel
Action: Upgrade
AI Analysis

Impact

Ankaref Innovation and Technology Inc.’s LIBRID/LIBREF contains a stored XSS vulnerability caused by improper neutralization of input when generating web pages. The flaw allows malicious scripts to be persisted and subsequently executed in the browsers of users who view the affected content, potentially enabling unauthorized actions or data exfiltration. The weakness is classified under CWE‑79.

Affected Systems

All installations of Ankaref’s LIBRID/LIBREF from version 2.01.0.2183 up to, but not including, 18.9.26.2319 are vulnerable. Users and administrators should verify the exact version deployed to assess exposure.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact. The EPSS score is below 1 %, reflecting a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires injection of script code into a field that is rendered by the management panel. Once stored, the payload will be delivered to any user who accesses the affected page, providing a persistent risk until the system is upgraded.

Generated by OpenCVE AI on September 23, 2026 at 17:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify the current LIBRID/LIBREF version on all installations and determine if it falls within the vulnerable range.
  • Upgrade to a version equal to or newer than 18.9.26.2319, which fixes the stored XSS flaw.
  • Restrict access to the management panel to trusted administrators and enforce strong authentication to reduce the risk of unauthorized script injection.

Generated by OpenCVE AI on September 23, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ankaref Innovation And Technology Inc.
Ankaref Innovation And Technology Inc. librid/libref
Vendors & Products Ankaref Innovation And Technology Inc.
Ankaref Innovation And Technology Inc. librid/libref

Thu, 10 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Ankaref Innovation And Technology Inc. Librid/libref
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-23T08:16:15.870Z

Reserved: 2026-06-19T06:27:18.042Z

Link: CVE-2026-12683

cve-icon Vulnrichment

Updated: 2026-09-10T17:07:34.702Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T14:16:59.963

Modified: 2026-09-23T09:17:07.490

Link: CVE-2026-12683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T17:45:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')