Description
Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts that execute in the browsers of affected users.
Related CPE's
Could not find any relations
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-79
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
6.8 · Medium
Information
Source identifier
5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
Vulnerability status
Deferred
Published
2026-10-08T09:16:42.413Z
23 hours agoLast modified
2026-10-08T21:35:53.890Z
11 hours ago