Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2026-23880
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OnboardLite has stored Cross-site Scripting issue that may lead to admin Account Take Over
Source: NVD (National Vulnerability Database)
Vulnerability Description
OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f have a stored cross-site scripting vulnerability that can be rendered to an admin when they attempt to migrate a user's discord account in the dashboard. Commit 1d32081a66f21bcf41df1ecb672490b13f6e429f patches the issue.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
OnboardLite 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OnboardLite是Hack@UCF开源的一个应用程序。 OnboardLite存在安全漏洞,该漏洞源于存在存储型跨站脚本漏洞,可能在管理员尝试在仪表板中迁移用户的Discord账户时渲染给管理员。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
HackUCFOnboardLite < 1d32081a66f21bcf41df1ecb672490b13f6e429f -
II. Public POCs for CVE-2026-23880
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2026-23880
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2026-23880

No comments yet


Leave a comment