A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
History

Fri, 27 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Webkul
Webkul krayin Crm
Weaknesses CWE-79
CPEs cpe:2.3:a:webkul:krayin_crm:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul krayin Crm
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
Description A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-09-27T00:00:00

Updated: 2024-09-27T19:12:38.360Z

Reserved: 2024-09-11T00:00:00

Link: CVE-2024-46367

cve-icon Vulnrichment

Updated: 2024-09-27T19:12:32.259Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-27T17:15:13.487

Modified: 2024-09-30T12:45:57.823

Link: CVE-2024-46367

cve-icon Redhat

No data.