ZeroHour

CVE-2024-46366

CVSS 3.1
8.8 high
EPSS
<1%p43
Published
()
Modified
Description

A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.

Vendors
webkul
Products
krayin crm
Weakness
CWE-1336
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.