PT-2026-3506 · Unknown · Onboardlite

Bestdevofc

·

Published

2026-01-19

·

Updated

2026-01-19

·

CVE-2026-23880

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OnboardLite versions prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f
Description OnboardLite is a membership lifecycle platform. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f contain a stored cross-site scripting issue. This issue can be triggered when an administrator attempts to migrate a user's discord account through the dashboard. The vulnerability allows malicious code to be executed in the context of an administrator's session.
Recommendations Update to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f or a later version.

Exploit

Fix

RCE

XSS

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2026-23880
GHSA-93W8-83CG-H89G

Affected Products

Onboardlite