Executive brief
Ankaref LIBRID/LIBREF is a library management system used by organizations to catalog and manage digital and physical resources. An attacker can inject malicious JavaScript code that gets stored in the system and then executed in the browsers of users who view affected pages, potentially allowing credential theft, session hijacking, or unauthorized actions on behalf of legitimate users.
Technical details
This vulnerability is a stored cross-site scripting (XSS) flaw in the web page generation functionality of LIBRID/LIBREF. The product fails to properly neutralize user-supplied input before rendering it in web pages, allowing attackers to inject and store arbitrary JavaScript code. An attacker with the ability to submit content to the system can craft malicious payloads that will execute whenever other users access the compromised pages. The vulnerability affects versions 2.01.0.2183 through 18.9.26.2318, with a fix available in version 18.9.26.2319 or later.
Affected products
- Ankaref Innovation and Technology Inc. LIBRID/LIBREF 2.01.0.2183 to 18.9.26.2318
Timeline
- 2026-09-10: disclosed