---
id: CVE-2026-89191
title: |-
  Unsanitised input in
  the "template name" field of SQLView KRIS's Workflow Template feature
  is rendered in "onclick" attributes on the main dashboard without
  proper server-side sanitisation, allowing an attacker with administrative
  access…
summary: |-
  Unsanitised input in
  the "template name" field of SQLView KRIS's Workflow Template feature
  is rendered in "onclick" attributes on the main dashboard without
  proper server-side sanitisation, allowing an attacker with administrative
  access…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
vendor: SQLView
product: SQLView KRIS
affected:
  - kris 4.6.4.4 and below
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T09:16:42.413'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89191'
references:
  - url: 'https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-136/'
    label: 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T09:24:18.599Z'
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T13:18:07.526627Z'
---

## Overview

Unsanitised input in
the "template name" field of SQLView KRIS's Workflow Template feature
is rendered in "onclick" attributes on the main dashboard without
proper server-side sanitisation, allowing an attacker with administrative
access to inject and store malicious scripts that execute in the browsers of
affected users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
