Stored XSS Vulnerability in AdaptiveGRC Product
CVE-2026-4313
2.4LOW
What is CVE-2026-4313?
The AdaptiveGRC product is susceptible to Stored Cross-Site Scripting through inadequate validation of text type fields in its forms. When an authenticated attacker crafts a malicious HTTP POST request, they can manipulate the text field's value, leading to the execution of arbitrary JavaScript in the browser of any user accessing the compromised form. This security flaw can potentially allow attackers to gain access to administrator authentication tokens, facilitating unauthorized actions with heightened privileges and leading to greater security breaches.
Affected Version(s)
AdaptiveGRC 5.420.00 < 5.420.66
AdaptiveGRC 5.420.00 < 5.444.119
AdaptiveGRC 5.420.00 < 5.448.116
