CVE-2026-89191

Published: Ott 08, 2026 Last Modified: Ott 08, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,8
Source: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

Unsanitised input in
the 'template name' field of SQLView KRIS's Workflow Template feature
is rendered in 'onclick' attributes on the main dashboard without
proper server-side sanitisation, allowing an attacker with administrative
access to inject and store malicious scripts that execute in the browsers of
affected users.

https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-136/