Impact
AdaptiveGRC is susceptible to stored cross-site scripting through any text input field. An authenticated user can submit crafted content that the server stores without validating or sanitizing. When another user – such as an administrator – views the affected page, the malicious script runs in the victim’s browser. Because the script can capture session cookies or authentication tokens, the attacker may acquire the administrator authentication token and perform actions with administrative privileges, potentially leading to full compromise of the system.
Affected Systems
The vulnerability affects C&F AdaptiveGRC releases before December 2025. The product is AdaptiveGRC, a governance, risk, and compliance platform. All versions released prior to December 2025 are susceptible; later releases contain the fix.
Risk and Exploitability
The CVSS base score is 2.4, indicating low overall severity, and the EPSS score is below 1%, suggesting exploitation likelihood is currently very low. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session that can post data to the server, meaning an attacker would first need valid user credentials. However, once authenticated, the attacker can inject arbitrary JavaScript into stored fields, obtaining administrative session data. Despite the low score, this could serve as a foothold for lateral movement or credential theft, so monitoring and timely patching remain advisable.
OpenCVE Enrichment