Stored Client-Side Template Injection Vulnerability in Krayin CRM by Krayin
CVE-2026-48541

5.1MEDIUM

Key Information:

Vendor

Krayin

Vendor
CVE Published:
24 September 2026

What is CVE-2026-48541?

Krayin CRM versions up to 2.2.6 are susceptible to a stored client-side template injection vulnerability. This issue enables authenticated attackers to inject malicious JavaScript into the application by exploiting the person name field, which processes Vue.js template syntax. By inserting specially crafted double-brace syntax, attackers can manipulate the Vue template compiler, allowing them to perform arbitrary JavaScript execution in the context of other users’ browsers. This could lead to various security risks, including unauthorized data access and user session hijacking for any user who views an infected person record.

Affected Version(s)

laravel-crm 0 <= 2.2.6

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aaron Amran Bin Amiruddin (@aaronamran)
.