PT-2026-3506 · Unknown · Onboardlite
Bestdevofc
·
Published
2026-01-19
·
Updated
2026-01-19
·
CVE-2026-23880
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
OnboardLite versions prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f
Description
OnboardLite is a membership lifecycle platform. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f contain a stored cross-site scripting issue. This issue can be triggered when an administrator attempts to migrate a user's discord account through the dashboard. The vulnerability allows malicious code to be executed in the context of an administrator's session.
Recommendations
Update to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f or a later version.
Exploit
Fix
RCE
XSS
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onboardlite