Impact
An input sanitization flaw in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.’s Library Information and Document Automation Program allows an attacker to inject malicious code into HTML attribute values generated by the web application. The flaw, classified as CWE‑79, enables the execution of arbitrary JavaScript in the context of a victim’s browser, potentially leading to session hijacking, credential theft or disclosure of sensitive information stored or displayed within the application.
Affected Systems
The vulnerability affects the Library Information and Document Automation Program prior to version 22.2. It impacts the web interface used for document and catalog management provided by Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Attackers are likely to exploit the flaw by submitting crafted inputs through the web application’s input fields, bypassing the server’s rendering logic. Successful exploitation grants the attacker the capability to run client‑side scripts in the victim’s browser session.
OpenCVE Enrichment