
CVE-2024-45932
https://notcve.org/view.php?id=CVE-2024-45932
07 Oct 2024 — Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. • http://TobeReleased.com • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-46366
https://notcve.org/view.php?id=CVE-2024-46366
27 Sep 2024 — A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. • https://gist.github.com/Tommywarren/89cef7f876ee897a4ff40a8b71b6208e • CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine •

CVE-2024-46367
https://notcve.org/view.php?id=CVE-2024-46367
27 Sep 2024 — A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. • https://gist.github.com/Tommywarren/4ac0c8f6e5d8584accd31b8277e55749 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-2925 – Webkul krayin crm Edit Person Page 2 cross site scripting
https://notcve.org/view.php?id=CVE-2023-2925
27 May 2023 — A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://drive.google.com/file/d/1t7JwP0Qyo6ye-2dt6XhA1ENHDwsnYjD3/view?usp=sharing • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •