Junglewise Threat Intelligence

CVE-2025-0875: PROLIZ OBS authorization bypass in Student Affairs Information System

CVE-2025-0875 · Severity: medium · CVSS 6.5 · Published 2025-09-22

Technologies: PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System).

Executive brief

A security vulnerability has been identified in the PROLIZ Student Affairs Information System (OBS), a platform used by educational institutions to manage student records and academic data. An attacker with basic user access could potentially bypass security controls to view sensitive information belonging to other users by manipulating web request parameters. This could lead to the unauthorized exposure of private student or staff data, impacting institutional privacy and compliance.

Technical details

An Authorization Bypass Through User-Controlled Key (Insecure Direct Object Reference) vulnerability exists in PROLIZ OBS before version v26.0328. The flaw (CWE-639) allows an authenticated attacker to perform parameter injection by modifying keys or identifiers within network requests. Because the application fails to properly validate that the requesting user has permission to access the object associated with the modified key, an attacker can retrieve sensitive information belonging to other entities. This vulnerability is exploitable over the network with low privileges and no user interaction. Users are advised to upgrade to version v26.0328 or later.

Affected products

  • PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) before v26.0328

Timeline

  • 2025-09-22: advisory: Initial disclosure by TR-CERT/USOM
  • 2025-09-22: disclosed

References