{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-89191", "assignerOrgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4", "state": "PUBLISHED", "assignerShortName": "CSA", "dateReserved": "2026-09-11T07:16:58.799Z", "datePublished": "2026-10-08T08:15:14.655Z", "dateUpdated": "2026-10-08T08:22:53.338Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "5f57b9bf-260d-4433-bf07-b6a79e9bb7d4", "shortName": "CSA", "dateUpdated": "2026-10-08T08:22:53.338Z" }, "title": "Stored Cross-Site Scripting in SQLView KRIS", "datePublic": "2026-10-08T08:07:00.000Z", "affected": [ { "vendor": "SQLView", "product": "SQLView KRIS", "versions": [ { "status": "affected", "version": "4.6.4.4 and below" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "Unsanitised input in\nthe \"template name\" field of SQLView KRIS's Workflow Template feature\nis rendered in \"onclick\" attributes on the main dashboard without\nproper server-side sanitisation, allowing an attacker with administrative\naccess to inject and store malicious scripts that execute in the browsers of\naffected users.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Unsanitised input in\nthe \"template name\" field of SQLView KRIS's Workflow Template feature\nis rendered in \"onclick\" attributes on the main dashboard without\nproper server-side sanitisation, allowing an attacker with administrative\naccess to inject and store malicious scripts that execute in the browsers of\naffected users." } ] } ], "references": [ { "url": "https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-136/" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "MEDIUM", "baseScore": 6.8, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" } } ], "solutions": [ { "lang": "en", "value": "SQLView, the product\nowner, has rolled out a fix for the reported vulnerability. Users and\nadministrators of affected product versions are advised to update to the latest\nversion promptly.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "SQLView, the product\nowner, has rolled out a fix for the reported vulnerability. Users and\nadministrators of affected product versions are advised to update to the latest\nversion promptly." } ] } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.5" } } } }