Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes.

This issue affects Library Information and Document Automation Program: before v22.2.
Published: 2026-09-04
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An input sanitization flaw in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.’s Library Information and Document Automation Program allows an attacker to inject malicious code into HTML attribute values generated by the web application. The flaw, classified as CWE‑79, enables the execution of arbitrary JavaScript in the context of a victim’s browser, potentially leading to session hijacking, credential theft or disclosure of sensitive information stored or displayed within the application.

Affected Systems

The vulnerability affects the Library Information and Document Automation Program prior to version 22.2. It impacts the web interface used for document and catalog management provided by Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. Attackers are likely to exploit the flaw by submitting crafted inputs through the web application’s input fields, bypassing the server’s rendering logic. Successful exploitation grants the attacker the capability to run client‑side scripts in the victim’s browser session.

Generated by OpenCVE AI on September 4, 2026 at 15:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch that removes the XSS vulnerability, or upgrade to v22.2 or later
  • If a patch is not yet available, enforce strict input validation and attribute value encoding for all user‑supplied data
  • Deploy a Content Security Policy that restricts script execution to trusted sources to reduce the impact of any remaining or unknown XSS vectors

Generated by OpenCVE AI on September 4, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library Information and Document Automation Program: before v22.2.
Title HTML Injection via Improper Input Sanitization in Yordam Informatics's Library Automation System
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-04T14:04:05.910Z

Reserved: 2026-08-13T12:41:14.633Z

Link: CVE-2026-19727

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T15:17:33.480

Modified: 2026-09-04T15:17:33.480

Link: CVE-2026-19727

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T16:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')