CVE-2026-12683 PUBLISHED

Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF

Assigner: TR-CERT
Reserved: 19.06.2026 Published: 10.09.2026 Updated: 10.09.2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS.

This issue affects LIBRID/LIBREF: from 2.01.0.2183 through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor Ankaref Innovation and Technology Inc.
Product LIBRID/LIBREF
Versions Default: unknown
  • affected from 2.01.0.2183 to 10092026 (incl.)

Credits

  • Ahmet DURMUŞ finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-592 Stored XSS