8.9
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Software Ltd. Co. OBS (Student Affairs Information System) allows Stored XSS.This issue affects OBS (Student Affairs Information System): before 25.0401.
AI Analysis
Stored Cross-site Scripting (XSS) vulnerability in OBS (Student Affairs Information System) allows attackers to inject malicious scripts
Basic Information
ID
CVE-2025-11956
Source
TR-CERT
Published
Nov 6, 2025 at 14:51
Modified
Nov 6, 2025 at 15:07
Affected Product
Vendor
Proliz Software Ltd. Co.
Product
OBS (Student Affairs Information System)
Version
before 25.0401
Affected Versions
Proliz Software Ltd. Co. OBS (Student Affairs Information System) 0
CWE Classification
AI Assessment
AI Score
8.9 / 10
AI Severity
High
Vendor
Proliz Software Ltd. Co.
Product
OBS (Student Affairs Information System)
Version
before 25.0401