Impact
This vulnerability arises from an inadequate password recovery mechanism in LIBRID/LIBREF, allowing attackers to reset user passwords without proper authentication. The flaw falls under CWE‑640, indicating improper authentication. An attacker exploiting this can gain unauthorized access to user accounts, potentially leading to data leakage, privilege escalation, or further compromise of the system.
Affected Systems
The affected product is Ankaref Innovation and Technology Inc.’s LIBRID/LIBREF. Versions from 2.01.0.2183 through 10092026 are vulnerable.
Risk and Exploitability
The CVSS score is 7.5, reflecting a high potential impact. No EPSS score is available, and the issue is not currently listed in the CISA KEV catalog. The likely attack vector is remote via the web interface’s password recovery feature, which an attacker can target after determining a username or email address. Given the lack of mitigation in the source code, exploitation is reasonably straightforward for an individual with information about a target account.
OpenCVE Enrichment