Executive brief
A security vulnerability exists in the PROLIZ Student Affairs Information System (OBS), a platform used by educational institutions to manage student records and academic data. An attacker can inject malicious scripts into the system that are then executed in the browsers of other users, such as administrators or students. This could lead to unauthorized access to sensitive student information, session hijacking, or the performance of unauthorized actions on behalf of legitimate users.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in PROLIZ OBS (Student Affairs Information System) due to improper neutralization of user-supplied input during web page generation. The flaw allows a remote attacker with low privileges to inject malicious JavaScript into the application's database. When other users view the affected pages, the script executes in their browser context. This can lead to full account takeover, data theft, or unauthorized modification of student records. The vulnerability is addressed in version v25.0401.
Affected products
- PROLIZ Computer Software Hardware Service Trade Ltd. Co. OBS (Student Affairs Information System) before v25.0401
Timeline
- 2025-09-25: advisory: Initial publication of the CVE record.
- 2026-06-05: other: CVE record was modified with updated descriptions and references.