PT-2026-82502 · Flowintel · Flowintel

·

CVE-2026-81814

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Flowintel versions 3.3.0 and later
Description Stored Cross-Site Scripting (XSS) occurs because calendar event titles are rendered using innerHTML. Since these titles are derived from case titles, a user with permissions to create or modify a case title can inject HTML or script-capable content. This content is subsequently executed by the browser when another user views the calendar. The issue involves the use of innerHTML to assign the arg.event.title variable.
Recommendations For versions 3.3.0 and later, update the software to replace the use of innerHTML with textContent when rendering the arg.event.title variable and the static download icon.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81814

Affected Products

Flowintel