Client-Side Template Injection Vulnerability Allows Privilege Escalation
CVE-2024-46366

8.8HIGH

Key Information:

Vendor

Webkul

Vendor
CVE Published:
27 September 2024

What is CVE-2024-46366?

A Client-side Template Injection (CSTI) vulnerability exists in Webkul Krayin CRM 1.3.0 that allows remote attackers to inject malicious code during the lead creation process. This vulnerability enables the execution of arbitrary client-side template code, which can result in privilege escalation for unauthorized users. By successfully exploiting this vulnerability, attackers may gain elevated permissions within the CRM system, potentially compromising sensitive data and application integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.