Stored Cross-Site Scripting Vulnerability in Vinna Process Monitor by Skilja
CVE-2026-41031
9.3CRITICAL
What is CVE-2026-41031?
The Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) has a vulnerability that allows an authenticated remote attacker with low privileges to insert malicious JavaScript code into the application. This vulnerability exposes the application's users to the risk of losing sensitive administrative access tokens and session credentials, which could lead to unauthorized access and exploitation of the system.
Affected Version(s)
Vinna Process Monitor 3.1.2 < 4.0.6
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michał Bartoszuk and Maciej Włodarczyk @STM Cyber
