Webkul Vulnerabilities and Affected Products
Vulnerabilities associated with krayin_crm.
Products
Clear product- QloApps5 vulnerabilities
- Bagisto3 vulnerabilities
- krayin_crm3 vulnerabilities
- Krayin CRM2 vulnerabilities
- Ajax Quiz1 vulnerability
- Medical Prescription Attachment Plugin for WooCommerce1 vulnerability
- uvdesk1 vulnerability
- WooCommerce Point of Sale1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization nameKrayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. CWE-79Oct 7, 2024 | CVSS-v4.0 | EPSS0.397% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-46367CRITICAL | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. CWE-79Sep 27, 2024 | CVSS9.6v3.1 | EPSS0.502% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-46366HIGH | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. CWE-1336Sep 27, 2024 | CVSS8.8v3.1 | EPSS0.502% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |