Executive brief
RELATE is a web-based courseware platform used for managing educational content and student participation. A security flaw allows students to inject malicious scripts into their profile names, which then execute in the browser of an administrator viewing the student list. This could allow a student to take over an administrator's account, potentially compromising the entire course platform and sensitive student data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the `ParticipationAdmin.get_user()` method within `course/admin.py`. The application uses `mark_safe` in conjunction with Python's `%` string formatting to render user-controlled data, effectively bypassing Django's automatic HTML escaping. An authenticated student can modify their `first_name` or `last_name` via the `/profile/` page to include malicious scripts. When an administrator views the Participation list in the Django admin panel, the unsanitized input is rendered, executing the script in the admin's context. The issue is fixed in commit 555f0efb1c5bd7531c07cd73724d7e566a81f620.
Affected products
- inducer RELATE versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620
Timeline
- 2026-05-16: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: CVE published to NVD