Junglewise Threat Intelligence

CVE-2025-10914: Proliz Software OBS reflected XSS in Student Affairs Information System

CVE-2025-10914 · Severity: high · CVSS 7.6 · Published 2025-10-23

Technologies: Proliz Software Ltd. Co. OBS (Student Affairs Information System). Vendors: Proliz Software Ltd. Co..

Executive brief

A security vulnerability has been identified in the Proliz Student Affairs Information System (OBS), a platform used by educational institutions to manage student records and academic data. This flaw allows attackers to perform reflected cross-site scripting (XSS) attacks, which could lead to the theft of user session cookies or unauthorized actions on behalf of students and staff. Organizations using this system should update to version V26.0401 or later to protect sensitive academic information and user accounts.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Proliz Software Ltd. Co. OBS (Student Affairs Information System) prior to version V26.0401. The application fails to properly neutralize user-supplied input during web page generation, allowing an unauthenticated remote attacker to inject malicious scripts. An exploit typically requires a victim to click a specially crafted link (User Interaction required). Successful exploitation can lead to the execution of arbitrary JavaScript in the context of the victim's browser session, potentially resulting in session hijacking or sensitive data disclosure. The issue is addressed in version V26.0401.

Affected products

  • Proliz Software Ltd. Co. OBS (Student Affairs Information System) before V26.0401

Timeline

  • 2025-10-23: advisory: Initial publication of CVE-2025-10914

References