CVE 7.3 HIGH

OnboardLite has stored Cross-site Scripting issue that may lead to admin Account Take Over_CVE-2026-23880

7.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Description

OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f have a stored cross-site scripting vulnerability that can be rendered to an admin when they attempt to migrate a user's discord account in the dashboard. Commit 1d32081a66f21bcf41df1ecb672490b13f6e429f patches the issue.

Basic Information

ID CVE-2026-23880
Source GitHub_M
Published Jan 19, 2026 at 20:55

Affected Product

Vendor HackUCF
Product OnboardLite
Version < 1d32081a66f21bcf41df1ecb672490b13f6e429f
Affected Versions HackUCF OnboardLite < 1d32081a66f21bcf41df1ecb672490b13f6e429f

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.