CVE-2024-46366

HIGH

Webkul Krayin Crm - Privilege Escalation

Title source: rule
STIX 2.1

Description

A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.

Scores

CVSS v3 8.8
EPSS 0.0056
EPSS Percentile 68.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1336
Status published
Products (1)
webkul/krayin_crm 1.3.0
Published Sep 27, 2024
Tracked Since Feb 18, 2026