Executive brief
EduAsist, an educational management platform, is vulnerable to a security flaw that could allow attackers to execute malicious scripts in a user's browser. This occurs when a user clicks a specially crafted link, potentially leading to unauthorized actions or the theft of session information. Organizations using this software should update to version 2.1 or later to protect their users' data and account integrity.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in KNOWHY EduAsist before version 2.1 due to improper neutralization of user-supplied input during web page generation. The vulnerability is exploitable via the network without authentication, though it requires user interaction (e.g., clicking a malicious link). An attacker can leverage this to execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or unauthorized data access. The issue was addressed in version 2.1.
Affected products
- KNOWHY Advanced Technology Trading Ltd. Co. EduAsist before v2.1
Timeline
- 2026-02-27: disclosed
- 2026-02-27: advisory