Executive brief
A critical security vulnerability has been identified in the Yordam Library Automation System, a platform used to manage library collections and operations. This flaw allows unauthorized individuals to manipulate the system's database over the internet without needing a username or password. An attacker could use this to steal sensitive patron data, modify library records, or disrupt the availability of the library's digital services.
Technical details
An SQL injection vulnerability exists in Yordam Informatics Yordam Library Automation System due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is reachable over the network and requires no prior authentication or user interaction. By sending specially crafted requests, an attacker can bypass security controls to view, modify, or delete data within the underlying database. The issue affects versions 21.5 and 21.6, and has been addressed in version 21.7.
Affected products
- Yordam Informatics Yordam Library Automation System 21.5 and 21.6 before 21.7
Timeline
- 2025-09-17: disclosed
- 2025-09-17: advisory