top of page
perceptive_background_267k.jpg

OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prio…

Published:

18 januari 2026 om 23:00:00

Alert date:

19 januari 2026 om 22:01:52

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies

OnboardLite, a membership lifecycle platform for University of Central Florida student organizations, contains a stored cross-site scripting (XSS) vulnerability in versions prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f. The vulnerability can be triggered when administrators attempt to migrate user Discord accounts through the dashboard. The XSS attack targets administrative users, potentially allowing malicious code execution in their browser sessions. The vulnerability has been patched in the specified commit. This represents a moderate security risk as it requires admin interaction but could lead to privilege escalation or session hijacking.

Technical details

Mitigation steps:

Affected products:

OnboardLite

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page