Executive brief
Yordam's Library Reservation System contains a missing authentication vulnerability that allows attackers to perform unauthorized operations on critical functions. An attacker can exploit this flaw to manipulate input data without proper access controls, potentially leading to unauthorized modifications of library reservation records or system data.
Technical details
The Library Reservation System prior to version 22.2 is vulnerable to missing authentication on critical functions. This allows unauthenticated or improperly authenticated users to invoke protected operations and manipulate input data. The vulnerability is accessible over the network and requires minimal preconditions. An attacker can leverage this to alter library reservation records, user data, or other critical system information without proper authorization. Upgrading to version 22.2 or later mitigates the issue.
Affected products
- Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System before v22.2
Timeline
- 2026-09-09: disclosed