CVE-2025-11950
Plain English Summary
AI-powered analysis for quick understanding
An attacker can exploit a vulnerability in EduAsist to inject malicious scripts into web pages, potentially stealing sensitive information from users or hijacking their sessions. This issue occurs when the application fails to properly handle user input, and it affects the platform until February 2026.
Technical Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Advanced Technology Trading Ltd. Co. EduAsist allows Reflected XSS.This issue affects EduAsist: through 27022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 27, 2026
about 1 month ago
Last Modified
Feb 28, 2026
about 1 month ago
Vendor
eduasist
Product
eduasist