{"id":"CVE-2026-89191","title":"Unsanitised input in\nthe \"template name\" field of SQLView KRIS's Workflow Template feature\nis rendered in \"onclick\" attributes on the main dashboard without\nproper server-side sanitisation, allowing an attacker with administrative\naccess…","summary":"Unsanitised input in\nthe \"template name\" field of SQLView KRIS's Workflow Template feature\nis rendered in \"onclick\" attributes on the main dashboard without\nproper server-side sanitisation, allowing an attacker with administrative\naccess…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H","vendor":"SQLView","product":"SQLView KRIS","affected":["kris 4.6.4.4 and below"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T09:16:42.413","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89191","references":[{"url":"https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-136/","label":"5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T09:24:18.599Z","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-08T13:18:07.526627Z"},"slug":"CVE-2026-89191","body":"## Overview\n\nUnsanitised input in\nthe \"template name\" field of SQLView KRIS's Workflow Template feature\nis rendered in \"onclick\" attributes on the main dashboard without\nproper server-side sanitisation, allowing an attacker with administrative\naccess to inject and store malicious scripts that execute in the browsers of\naffected users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}