


Perceptive Security
SOC/SIEM Consultancy

OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prio…
Published:
18 januari 2026 om 23:00:00
Alert date:
19 januari 2026 om 22:01:52
Source:
nvd.nist.gov
Web Technologies
OnboardLite, a membership lifecycle platform for University of Central Florida student organizations, contains a stored cross-site scripting (XSS) vulnerability in versions prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f. The vulnerability can be triggered when administrators attempt to migrate user Discord accounts through the dashboard. The XSS attack targets administrative users, potentially allowing malicious code execution in their browser sessions. The vulnerability has been patched in the specified commit. This represents a moderate security risk as it requires admin interaction but could lead to privilege escalation or session hijacking.
Technical details
Mitigation steps:
Affected products:
OnboardLite
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-23880
https://github.com/HackUCF/OnboardLite/commit/1d32081a66f21bcf41df1ecb672490b13f6e429f
https://github.com/HackUCF/OnboardLite/security/advisories/GHSA-93w8-83cg-h89g
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
