PT-2024-31971 · Webkul · Webkul Krayin Crm
Avihay Eldad
+1
·
Published
2024-09-27
·
Updated
2025-07-09
·
CVE-2024-46367
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Webkul Krayin CRM version 1.3.0
Description
A Stored Cross-Site Scripting (XSS) issue allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the
username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.Recommendations
For Webkul Krayin CRM version 1.3.0, consider disabling the submission of user input in the
username field until a patch is available to prevent the injection of malicious JavaScript code. Restrict access to sensitive areas of the CRM system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Fix
LPE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webkul Krayin Crm