Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-89191

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
08/10/2026
Última modificación:
08/10/2026

Descripción

*** Pendiente de traducción *** Unsanitised input in<br /> the "template name" field of SQLView KRIS&amp;#39;s Workflow Template feature<br /> is rendered in "onclick" attributes on the main dashboard without<br /> proper server-side sanitisation, allowing an attacker with administrative<br /> access to inject and store malicious scripts that execute in the browsers of<br /> affected users.

Referencias a soluciones, herramientas e información