Executive brief
Proliz OBS, a student information system used by educational institutions, contains a security flaw that allows unauthorized access to sensitive data. An attacker can bypass access controls to view information or use functions they should not be able to reach. This could lead to the exposure of private student or administrative records and potentially disrupt school operations.
Technical details
A vulnerability exists in Proliz OBS before version 3.6.0 involving the insertion of sensitive information into sent data (CWE-201) and improper enforcement of Access Control Lists (ACLs). The flaw allows a remote, unauthenticated attacker to access functionality and data that should be restricted to authorized users. The root cause is a failure to properly constrain functionality based on user permissions, combined with the leakage of sensitive data in network responses. This can be exploited over the network without user interaction. A fix is available in version 3.6.0.
Affected products
- Proliz Software Ltd. Co. OBS (Student Information System) before v3.6.0
Timeline
- 2026-07-17: disclosed
- 2026-07-17: advisory: NVD publication date