PT-2024-31970 · Webkul · Webkul Krayin Crm
Avihay Eldad
+1
·
Published
2024-09-27
·
Updated
2024-10-02
·
CVE-2024-46366
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Webkul Krayin CRM version 1.3.0
Description
A Client-side Template Injection (CSTI) vulnerability allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
Recommendations
For Webkul Krayin CRM version 1.3.0, consider disabling the lead creation process until a patch is available to prevent exploitation of the CSTI vulnerability. Restrict access to the CRM system to minimize the risk of privilege escalation. Avoid using the vulnerable template injection functionality in the lead creation process until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webkul Krayin Crm