Junglewise Threat Intelligence

CVE-2025-14347: Proliz Software OBS reflected XSS in Student Affairs Information System

CVE-2025-14347 · Severity: medium · CVSS 6.3 · Published 2025-12-17

Executive brief

A security vulnerability exists in the Proliz Student Affairs Information System (OBS), a platform used by educational institutions to manage student records and academic data. An attacker could use this flaw to execute malicious scripts in the browser of a logged-in user, potentially leading to the theft of sensitive session information or unauthorized actions on behalf of students or staff. This issue has been addressed in version 26.5009.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Proliz Software Ltd. OBS (Student Affairs Information System) before version 26.5009. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An attacker can exploit this by tricking an authenticated user into clicking a specially crafted link, allowing the execution of arbitrary JavaScript in the context of the victim's browser session. According to the CVSS vector, the attack requires low privileges and user interaction, and it can result in high confidentiality impact. The issue is resolved in version 26.5009.

Affected products

  • Proliz Software Ltd. OBS (Student Affairs Information System) before 26.5009

Timeline

  • 2025-12-17: advisory: Initial publication by TR-CERT/USOM
  • 2025-12-17: disclosed
  • 2026-06-04: other: NVD record updated

References