CVE-2025-11950

Plain English Summary

AI-powered analysis for quick understanding

An attacker can exploit a vulnerability in EduAsist to inject malicious scripts into web pages, potentially stealing sensitive information from users or hijacking their sessions. This issue occurs when the application fails to properly handle user input, and it affects the platform until February 2026.

Technical Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Advanced Technology Trading Ltd. Co. EduAsist allows Reflected XSS.This issue affects EduAsist: through 27022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactNone
ScopeChanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$862($500-$1K)
Vendor Response
Grade APatched in 0 days

Quick Information

Published

Feb 27, 2026

about 1 month ago

Last Modified

Feb 28, 2026

about 1 month ago

Vendor

eduasist

Product

eduasist