Executive brief
A security flaw has been identified in the Yordam Library Automation System, a platform used to manage library resources and member data. The vulnerability involves improperly configured access controls, which could allow unauthorized individuals to bypass security levels. If exploited, this could lead to the unauthorized viewing, modification, or deletion of sensitive library records and user information.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the Yordam Library Automation System due to improperly configured access control security levels. The flaw allows a remote attacker to bypass intended access restrictions. According to the CVSS vector, the attack is network-reachable and requires low complexity, though it involves some level of user interaction. Successful exploitation could grant the attacker high levels of confidentiality, integrity, and availability impact, effectively allowing unauthorized administrative actions or data exfiltration. The issue affects versions 19.5 through 22.1, and users are advised to update to a version beyond 22.1.
Affected products
- Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System v.19.5 to v.22.1
Timeline
- 2026-05-14: disclosed: Initial advisory publication by TR-CERT
- 2026-05-14: advisory: NVD publication date