PT-2026-36081 · Webkul · Krayin Crm
Published
2026-04-30
·
Updated
2026-05-07
·
CVE-2026-36341
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Webkul Krayin CRM version 2.1.5
Description
A Cross-Site Scripting (XSS) issue occurs due to improper sanitization of user-supplied input in the comment field during activity creation. This allows for HTML injection via the "/admin/activities/create" endpoint using the
comment variable.Recommendations
Update Webkul Krayin CRM to a version later than 2.1.5.
As a temporary workaround, restrict access to the "/admin/activities/create" endpoint or avoid entering untrusted data into the
comment field.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Krayin Crm