Stored XSS Vulnerability in Webkul Krayin CRM 1.3.0
CVE-2024-46367
9.6CRITICAL
What is CVE-2024-46367?
A vulnerability exists in Webkul Krayin CRM 1.3.0, allowing remote attackers to execute arbitrary JavaScript code by injecting malicious payloads into the username field. If exploited, this Stored Cross-Site Scripting (XSS) vulnerability can lead to unauthorized privilege escalation, enabling attackers to gain elevated permissions and compromise the integrity of the CRM system.
