SQLView KRIS – Stored Cross-Site Scripting Vulnerability in Workflow Template Feature
8 October 2026
A vulnerability has been discovered in the records management application "SQLView KRIS". The product owner has rolled out a fix for the reported vulnerability. Special thanks to the researcher and SQLView for coordinating through CSA's Responsible Vulnerability Disclosure Policy.
Background
SQLView KRIS is a records management application used to organise and manage organisational records and workflows, including the creation and management of workflow templates.
CVE ID – Description
CVE-2026-89191 | 6.8 (Medium) – Unsanitised input in the "template name" field of SQLView KRIS's Workflow Template feature is rendered in "onclick" attributes on the main dashboard without proper server-side sanitisation, allowing an attacker with administrative access to inject and store malicious scripts that execute in the browsers of affected users.
Affected Versions
The vulnerability affects SQLView KRIS version 4.6.4.4 and below.
Mitigation
SQLView, the product owner, has rolled out a fix for the reported vulnerability. Users and administrators of affected product versions are advised to update to the latest version promptly.
Timeline
2026-06-18 – Vendor Disclosure
2026-08-28 – Vendor Patched
2026-10-08 – Public Release
Credit
Discovered by Yong Kai Wen
