CVE-2026-89191
EUVD-2026-9480408.10.2026, 09:16
Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts that execute in the browsers of affected users.
Awaiting analysis
This vulnerability is currently awaiting analysis.