Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-89191

MEDIUM · 6.8 CVSS Gepubliceerd: CWE-79

Beschrijving

Unsanitised input in
the "template name" field of SQLView KRIS's Workflow Template feature
is rendered in "onclick" attributes on the main dashboard without
proper server-side sanitisation, allowing an attacker with administrative
access to inject and store malicious scripts that execute in the browsers of
affected users.

References