Executive brief
LIBRID/LIBREF is a web application used for digital document management and reference. The vulnerability allows an attacker to inject malicious scripts that are stored on the server and executed in users' browsers when they view the affected content, potentially leading to session hijacking, data theft, or unauthorized actions on behalf of legitimate users.
Technical details
This is a stored cross-site scripting (XSS) vulnerability resulting from improper neutralization of user-supplied input during web page generation. The vulnerability exists in LIBRID/LIBREF versions 2.01.0.2183 through 18.9.26.2318 and is fixed in 18.9.26.2319. An attacker can inject malicious HTML/JavaScript payloads that are persisted in the application and executed in the browsers of users who access the compromised content. No special privileges or user interaction beyond normal application use is required for exploitation, making this a network-accessible persistent XSS vector. Patch 18.9.26.2319 or later should be applied immediately.
Affected products
- Ankaref Innovation and Technology Inc. LIBRID/LIBREF 2.01.0.2183 through 18.9.26.2318
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixed in version 18.9.26.2319