安卡雷夫创新技术公司(Ankaref Innovation and Technology Inc.)的 LIBRID/LIBREF 产品中存在“网页生成时输入未正确净化(跨站脚本,Cross-site scripting)”漏洞,导致可存储型 XSS(Stored XSS)。 该问题影响版本:从 2.01.0.2183 到 10092026。 注:厂商在披露前已被联系,但对方未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ankaref Innovation and Technology Inc. | LIBRID/LIBREF | 2.01.0.2183 ~ 10092026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6285 | 7.5 HIGH | Improper Authentication in Ankaref's LIBRID/LIBREF |
| CVE-2026-12682 | 5.4 MEDIUM | Stored XSS in Ankaref's LIBRID/LIBREF |
No comments yet