PT-2026-34874 · Unknown · Adaptivegrc
Antoni Kwietniewski
·
Published
2026-04-24
·
Updated
2026-04-25
·
CVE-2026-4313
CVSS v4.0
2.4
Low
| Vector | AV:A/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
AdaptiveGRC versions prior to December 2025
Description
Stored Cross-Site Scripting (XSS) occurs via text type fields across forms. An authenticated attacker can modify the value of a text field in an HTTP POST request. Due to improper parameter validation by the server, arbitrary JavaScript can be executed in the victim's browser. This may allow an attacker to obtain the administrator authentication token and perform actions with administrative privileges, potentially leading to further compromise.
Recommendations
Update to a version released in December 2025 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adaptivegrc