Impact
Krayin CRM through version 2.2.6 allows an authenticated user to insert Vue.js template expressions into the product name field, creating a stored client‑side template injection vulnerability. The injected expression can traverse the prototype chain to obtain the Function constructor and run arbitrary JavaScript within the context of any browser viewing the product record. This results in cross‑site scripting that can be used to steal session cookies, deface pages, or perform further client‑side attacks.
Affected Systems
The vulnerability affects Krayin CRM version 2.2.6, with the relevant product being the Laravel‑CRM application sold by Krayin. No other versions are explicitly noted as affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score is not available, and the flaw is not listed in CISA's KEV catalog. The attack requires an authenticated user to create or edit a product name, after which any user who views that product is impacted. Because it is a client‑side issue, the potential impact is limited to the victim’s browser, but the exploit can still lead to credential theft and session hijacking. Overall, the risk is moderate with a realistic chance of exploitation in environments where authentication is weak or internal users are used maliciously.
OpenCVE Enrichment