Executive brief
A cross-site scripting (XSS) vulnerability exists in Ubit Information Technologies STOYS, a platform used for educational management and student information. An attacker could use this flaw to inject malicious scripts into web pages viewed by other users. This could lead to unauthorized actions being performed in a user's session or the defacement of the web interface.
Technical details
A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in Ubit Information Technologies STOYS from version 2 up to (but not including) version 20250916. The flaw stems from the application's failure to properly neutralize user-supplied input before it is rendered in web pages. An authenticated attacker with low privileges can exploit this over the network to inject and execute arbitrary scripts in the context of a victim's browser. While the CVSS vector indicates no user interaction is required (UI:N), XSS typically impacts the integrity of the session. As of the advisory date, the vendor had not confirmed the completion of a fix within the reporting timeframe.
Affected products
- Ubit Information Technologies STOYS From 2 before 20250916
Timeline
- 2025-09-16: advisory: Initial disclosure by TR-CERT (USOM)
- 2025-09-16: disclosed