Cross-Site Scripting Vulnerability in Library Information and Document Automation Program by Yordam Information Technology
CVE-2026-19727

6.1MEDIUM

What is CVE-2026-19727?

A vulnerability exists in the Library Information and Document Automation Program developed by Yordam Information Technology, which allows for improper neutralization of input during web page generation. This flaw enables malicious users to exploit cross-site scripting (XSS) attacks, specifically targeting HTML attributes. As a result, attackers can potentially execute unauthorized scripts in the context of users' browsers, leading to data theft or session hijacking. This vulnerability impacts versions of the product prior to v22.2, underscoring the importance of updating to mitigate the associated risks.

Affected Version(s)

Library Information and Document Automation Program 0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

İremnur YILMAZ
.