PT-2026-102307 · Unknown · Av Book Library

·

CVE-2026-101111

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Book Library (Free) versions prior to 6.4.6
Description Reflected Cross-Site Scripting occurs in the public book-detail page template located at site/views/view book/tmpl/default.php. The application echoes the raw title request parameter directly into a double-quoted HTML attribute without using any escaping functions. An attacker can provide a value containing a double quote to close the attribute prematurely, allowing the execution of arbitrary HTML or JavaScript.
Recommendations Update Book Library (Free) to version 6.4.6 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101111

Affected Products

Av Book Library