PT-2026-34874 · Unknown · Adaptivegrc

Antoni Kwietniewski

·

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-4313

CVSS v4.0

2.4

Low

VectorAV:A/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions AdaptiveGRC versions prior to December 2025
Description Stored Cross-Site Scripting (XSS) occurs via text type fields across forms. An authenticated attacker can modify the value of a text field in an HTTP POST request. Due to improper parameter validation by the server, arbitrary JavaScript can be executed in the victim's browser. This may allow an attacker to obtain the administrator authentication token and perform actions with administrative privileges, potentially leading to further compromise.
Recommendations Update to a version released in December 2025 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-4313

Affected Products

Adaptivegrc