CVE-2024-46367

A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
CVSS

No CVSS.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkul:krayin_crm:1.3.0:*:*:*:*:*:*:*

History

09 Jul 2025, 17:41

Type Values Removed Values Added
References () https://gist.github.com/Tommywarren/4ac0c8f6e5d8584accd31b8277e55749 - () https://gist.github.com/Tommywarren/4ac0c8f6e5d8584accd31b8277e55749 - Third Party Advisory
CPE cpe:2.3:a:webkul:krayin_crm:1.3.0:*:*:*:*:*:*:*
First Time Webkul krayin Crm
Webkul

27 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 17:15

Updated : 2025-07-09 17:41


NVD link : CVE-2024-46367

Mitre link : CVE-2024-46367


JSON object : View

Products Affected

webkul

  • krayin_crm
CWE

No CWE.