PT-2026-3506 · Unknown · Onboardlite
Bestdevofc
·
Publicado
2026-01-19
·
Atualizado
2026-01-19
·
CVE-2026-23880
CVSS v3.1
7.3
Alta
| Vetor | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OnboardLite versions prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f
Description
OnboardLite is a membership lifecycle platform. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f contain a stored cross-site scripting issue. This issue can be triggered when an administrator attempts to migrate a user's discord account through the dashboard. The vulnerability allows malicious code to be executed in the context of an administrator's session.
Recommendations
Update to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f or a later version.
Exploit
Correção
RCE
XSS
Improper Encoding or Escaping of Output
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Onboardlite