CVE-2024-46367

A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
Configurations

No configuration.

History

27 Sep 2024, 20:35

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-27 17:15

Updated : 2024-09-30 12:45


NVD link : CVE-2024-46367

Mitre link : CVE-2024-46367

CVE.ORG link : CVE-2024-46367


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')