Executive brief
Yordam Library Information and Document Automation Program is a document management system used by organizations to store and retrieve information. The software fails to properly sanitize user input when generating web pages, allowing attackers to inject malicious scripts that execute in users' browsers. This could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of affected users.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in Yordam Library Information and Document Automation Program that specifically targets HTML attributes during web page generation. The root cause is improper input neutralization when processing user-supplied data that is reflected back in HTML attribute contexts. This is a stored or reflected XSS attack requiring no authentication; an attacker can craft a malicious URL or inject content that, when viewed by a user, executes arbitrary JavaScript in the victim's browser within the application's security context. The vulnerability affects versions prior to v22.2, and a patch is available in the current version.
Affected products
- Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program before v22.2
Timeline
- 2026-09-04: disclosed