CVE-2024-46366

A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
Configurations

No configuration.

History

No history.

Information

Published : 2024-09-27 17:15

Updated : 2024-09-30 12:45


NVD link : CVE-2024-46366

Mitre link : CVE-2024-46366

CVE.ORG link : CVE-2024-46366


JSON object : View

Products Affected

No product.

CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine