Executive brief
Yordam Information Technology's Library Information and Document Automation Program is used for managing library catalogues and digital document systems. The product contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts into web pages, potentially enabling content spoofing, unauthorized data access, or credential theft from users of the library system.
Technical details
This is a reflected or stored cross-site scripting (XSS) vulnerability caused by improper neutralization of user-supplied input during web page generation in the Library Information and Document Automation Program. The vulnerability allows an attacker to inject arbitrary JavaScript code that executes in the browser context of authenticated or unauthenticated users. Attack vectors likely include malicious URLs or crafted input fields within the application interface. The vulnerability affects versions from 22.1 through versions before 22.2, where a patch is expected to be available. No public exploit code is known to be actively used in the wild.
Affected products
- Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program 22.1 before 22.2
Timeline
- 2026-09-04: disclosed