A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
History

Fri, 27 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Webkul
Webkul krayin Crm
Weaknesses CWE-1336
CPEs cpe:2.3:a:webkul:krayin_crm:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul krayin Crm
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
Description A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-27T00:00:00

Updated: 2024-09-27T19:15:08.549Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-46366

cve-icon Vulnrichment

Updated: 2024-09-27T19:15:02.699Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-27T17:15:13.400

Modified: 2024-09-30T12:45:57.823

Link: CVE-2024-46366

cve-icon Redhat

No data.