Impact
Krayin CRM applications prior to version 2.2.6 allow a stored client‑side template injection flaw. By inserting Vue.js double‑brace syntax into the web form description field, an attacker can reach the Vue template compiler, traverse the prototype chain to obtain the Function constructor, and then execute arbitrary JavaScript with the origin of the vulnerable application. This enables attackers to compromise confidentiality and integrity for users who view the affected form – potential cookie theft, session hijacking, defacement, or further client‑side attacks within the trusted application context.
Affected Systems
The vulnerability exists in Krayin CRM, identified by the vendor product name krayin:laravel-crm, for all releases through 2.2.6. Users running version 2.2.6 or earlier are affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity and the EPSS score is not available, so the likelihood of exploitation cannot be quantified from this data. The vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation yet. The likely attack vector requires an authenticated user capable of creating or editing a web form; after injection the code runs in the browsers of any user who views that form. This is a client‑side template injection vulnerability (CWE‑79). Because the flaw is stored, all users that load the page are impacted, making this a potentially high‑impact threat for organizations that allow such form creation.
OpenCVE Enrichment