Junglewise Threat Intelligence

CVE-2025-11956: Proliz OBS stored XSS in Student Affairs Information System

CVE-2025-11956 · Severity: high · CVSS 8.9 · Published 2025-11-06

Technologies: Proliz Software Ltd. Co. OBS (Student Affairs Information System). Vendors: Proliz Software Ltd. Co..

Executive brief

A security vulnerability exists in the Proliz OBS Student Affairs Information System, a platform used by educational institutions to manage student records and academic data. An attacker with basic user access can inject malicious scripts that are permanently stored on the system and executed when other users, such as administrators or students, view certain pages. This could lead to the theft of sensitive session information, unauthorized access to student records, or the performance of actions on behalf of other users.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Proliz Software Ltd. Co. OBS (Student Affairs Information System) due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability allows an authenticated attacker with low privileges to inject malicious JavaScript into the application's database. When other users navigate to the affected pages, the script executes in their browser context. This can lead to session hijacking, sensitive data disclosure, or unauthorized administrative actions. The issue is resolved in version 25.0401.

Affected products

  • Proliz Software Ltd. Co. OBS (Student Affairs Information System) before 25.0401

Timeline

  • 2025-11-06: disclosed
  • 2025-11-06: advisory

References