Impact
The vulnerability lies in the Workflow Template feature of SQLView KRIS, where unsanitised input supplied to the "template name" field is rendered directly into "onclick" attributes on the main dashboard. This flaw allows an attacker who controls an administrative account to store malicious scripts that will execute in the browsers of any user who views the affected dashboard. The consequence is the execution of arbitrary client‑side code, exposing users to potential phishing, session hijacking or further compromise of the environment. The weakness is a classic stored cross‑site scripting flaw, classified as CWE‑79.
Affected Systems
SQLView KRIS is the affected product. No specific version information is provided; all deployed instances of SQLView KRIS are potentially vulnerable until patched.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity vulnerability. The EPSS score is not available, making it difficult to gauge current exploitation likelihood, and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess administrative rights to the application, limiting the attack surface to organizations that have not secured privileged accounts or are vulnerable to compromising those credentials. Once an attacker has such access, the stored XSS can be executed against any logged‑in user who views the impacted dashboard.
OpenCVE Enrichment