CVE-2026-89191
MEDIUM
6,8
Source: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
Unsanitised input in
the 'template name' field of SQLView KRIS's Workflow Template feature
is rendered in 'onclick' attributes on the main dashboard without
proper server-side sanitisation, allowing an attacker with administrative
access to inject and store malicious scripts that execute in the browsers of
affected users.
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-136/