Executive brief
The Library Information and Document Automation Program, used by organizations for library and document management, contains an open redirect vulnerability that allows attackers to redirect users to malicious websites. This could be exploited in phishing campaigns to trick users into visiting attacker-controlled sites, potentially leading to credential theft or malware distribution.
Technical details
The vulnerability is an open redirect flaw (CWE-601) in the Library Information and Document Automation Program that allows an attacker to craft a malicious URL with a redirect parameter pointing to an untrusted site. When a user clicks the link or is redirected through the application, they are taken to the attacker's site instead of a legitimate destination. The vulnerability requires user interaction (clicking a malicious link) and can be exploited remotely over the network. The flaw affects versions from v22.1 before v22.2, with a patch available in v22.2 and later.
Affected products
- Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program v22.1 to before v22.2
Timeline
- 2026-09-09: disclosed