PT-2026-45555 · Kiteworks · Kiteworks
Icare
+2
·
Published
2026-06-01
·
Updated
2026-06-03
·
CVE-2026-24751
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Kiteworks versions prior to 9.3.0
Description
A reflected Cross-Site Scripting (XSS) issue in Kiteworks Secure Data Forms allows an external attacker to trick a user into executing arbitrary JavaScript code. Cross-Site Scripting is a flaw where malicious scripts are injected into otherwise trusted websites.
Recommendations
Update to version 9.3.0 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiteworks