XSS Vulnerability in SQLView KRIS Workflow Template Feature by Unknown Vendor
CVE-2026-89191

6.8MEDIUM

Key Information:

Vendor

Sqlview

Vendor
CVE Published:
8 October 2026

What is CVE-2026-89191?

The SQLView KRIS Workflow Template feature is susceptible to Cross-Site Scripting (XSS) attacks due to unsanitised input in the 'template name' field. An attacker with administrative privileges can exploit this vulnerability to store and execute malicious scripts within the 'onclick' attributes on the main dashboard. Consequently, unsuspecting users with access can have their browsers compromised, leading to potential data breaches and unauthorized actions.

Affected Version(s)

SQLView KRIS 4.6.4.4 and below

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.