Executive brief
Kiteworks, a platform for secure file sharing and private data networking, contains a security flaw in its Secure Data Forms component. An authorized user could inject malicious scripts into form configuration pages, which would then run in the browsers of other users who view those pages. This could lead to unauthorized access to user sessions or the theft of sensitive information within the platform.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the 'Thank You Page' configuration of Kiteworks Secure Data Forms. The root cause is improper neutralization of user-controllable input (CWE-79) before it is rendered in the web interface. An authenticated attacker with low privileges can inject malicious JavaScript that executes in the context of other users' sessions when they interact with the affected form page. Exploitation requires network access and minimal user interaction. The vulnerability is addressed in Kiteworks version 9.3.0.
Affected products
- Kiteworks Secure Data Forms < 9.3.0
Timeline
- 2026-05-27: advisory: Vendor advisory published via GitHub
- 2026-06-01: disclosed: CVE published to NVD dataset