Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 3 min 124 bronnen 3 kritiek 4 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-102109

HIGH · 7.1 CVSS Gepubliceerd: CWE-89

Beschrijving

A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature is in use.

References