Sceawere
Vulnerability Detail
CVE-2026-89191UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQLView KRIS Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.8
- Creation Date
- 3h ago
- Vendor
- SQLView
- Product
- SQLView KRIS
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts that execute in the browsers of affected users.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.8",
"pubDate": "2026-10-08T09:16:42.413Z",
"pubdate": "2026-10-08T09:16:42.413Z",
"executiveSummary": "This vulnerability is identified as a Stored Cross-Site Scripting (XSS) flaw within the SQLView KRIS Workflow Template feature. The issue arises from insufficient server-side sanitization of user-supplied data in the 'template name' field.\nBy injecting malicious JavaScript payloads into this field, an attacker with administrative privileges can compromise the sessions of other users who view the main dashboard where the payload is rendered.\nThe vulnerability manifests because the application reflects the unsanitized input directly into an 'onclick' HTML event attribute. When a legitimate user triggers this event, the injected script executes within the context of the user's browser session.\nThe impact includes potential session hijacking, unauthorized actions performed on behalf of the victim, theft of sensitive information, or the redirection of users to malicious external domains.\nExploitation requires administrative-level access to the Workflow Template configuration, making this an elevation of privilege or malicious insider threat scenario. Once stored, the payload executes automatically for any user interacting with the compromised dashboard element.",
"technicalDetails": "The root cause of this vulnerability is improper input validation and output encoding in the SQLView KRIS Workflow Template module. The 'template name' field accepts arbitrary string input without stripping dangerous characters or implementing context-aware output escaping.\nWhen a template is created or updated, the application persists the raw input string directly into the backend database. Subsequently, when the main dashboard component retrieves this data, it is reflected directly into an 'onclick' attribute of an HTML element without applying necessary security filters.\nThe exploitation flow proceeds as follows: First, an attacker with administrative privileges navigates to the Workflow Template management interface. Second, the attacker inputs a crafted JavaScript payload into the 'template name' field, such as \"'); alert(document.cookie); //\". Third, the application saves this string as a legitimate template name. Finally, when any user navigates to the main dashboard, the application renders the injected payload within the 'onclick' attribute. As soon as the user clicks the affected element, the JavaScript context is broken, and the malicious code is executed in the browser session of the victim.\nBecause the payload resides within the 'onclick' event handler, standard HTML entity encoding may be insufficient if it does not account for the JavaScript execution context. The execution occurs within the origin of the SQLView KRIS instance, granting the attacker access to the document object model (DOM), session cookies, and local storage associated with the application.\nThis vulnerability poses a significant risk to the integrity and confidentiality of the application, as it allows for the exfiltration of session tokens or the forced execution of administrative commands if the victim is a high-privileged user. Given the nature of the storage, the payload is persistent and will affect all users until the specific template name is purged from the database by an authorized administrator."
}