Ankaref Innovation and Technology Inc. 的 LIBRID/LIBREF 存在“弱密码找回机制(忘记密码场景)”漏洞,攻击者可利用该机制进行密码找回的滥用/利用。 该问题影响 LIBRID/LIBREF 的以下版本:从 2.01.0.2183 至 10092026。 注意:发布方曾提前联系供应商,但供应商未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Ankaref Innovation and Technology Inc. | LIBRID/LIBREF | 2.01.0.2183 ~ 10092026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12683 | 5.4 MEDIUM | Stored XSS Yönetim panel in Ankaref's LIBRID/LIBREF |
| CVE-2026-12682 | 5.4 MEDIUM | Stored XSS in Ankaref's LIBRID/LIBREF |
No comments yet