Impact
Cross‑Site Scripting arises because the application fails to neutralise user‑supplied input before rendering it in a web page. An attacker can inject arbitrary HTML or JavaScript that is reflected back to the victim, allowing the spoofing of page content, redirection of users, or capture of sensitive information. The flaw is a classic content‑spoofing XSS vulnerability classified by CWE‑79.
Affected Systems
Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. offers a Library Information and Document Automation Program. Versions beginning with 22.1 up to, but not including, 22.2 contain the vulnerability. Users of these releases should confirm the installed version and plan an upgrade to a version that has been hardened against reflected XSS.
Risk and Exploitability
Based on the description, it is inferred that the attack vector is a reflected form on a publicly reachable web interface. The CVSS score of 6.1 categorises the vulnerability as medium severity. No EPSS score is provided and the flaw is not listed in the CISA KEV catalog, signalling a low public exploit probability. Because the attack vector is a reflected form on a publicly reachable web interface, an attacker who can guess valid input can target any user session exposed to the vulnerable page. The lack of privilege escalation or authentication bypass limits the impact to the user’s session, but the possibility of phishing or credential theft remains significant.
OpenCVE Enrichment