Impact
Krayin CRM before version 2.2.6 is vulnerable to a stored client‑side template injection whereby authenticated users can insert Vue.js template expressions into the contact name field. The injected expression is compiled by the Vue template engine, allowing prototype chain traversal to obtain the Function constructor and execute arbitrary JavaScript in every browser that loads the affected record. This flaw enables cross‑site scripting that runs with the application origin, allowing attackers to steal user data, manipulate the UI, or perform additional malicious actions within the legitimate user session.
Affected Systems
The vulnerability affects Krayin CRM for Laravel, specifically versions up to and including 2.2.6. Users running any of these releases should verify their installation and determine whether an update is available.
Risk and Exploitability
The CVSS v3.1 score is 5.1, indicating a moderate impact. EPSS data is not available and the vulnerability is not listed in CISA KEV, suggesting limited publicly known exploitation. Attackers must be authenticated and have permission to edit contact records, making the vulnerability exploitable only in environments with insufficient access controls. Once exploited, the browser runs attacker‑supplied code in the application context, compromising confidentiality, integrity, and availability for all users who view the record.
OpenCVE Enrichment