Stored Client-Side Template Injection Vulnerability in Krayin CRM by Krayin
CVE-2026-48541
5.1MEDIUM
What is CVE-2026-48541?
Krayin CRM versions up to 2.2.6 are susceptible to a stored client-side template injection vulnerability. This issue enables authenticated attackers to inject malicious JavaScript into the application by exploiting the person name field, which processes Vue.js template syntax. By inserting specially crafted double-brace syntax, attackers can manipulate the Vue template compiler, allowing them to perform arbitrary JavaScript execution in the context of other users’ browsers. This could lead to various security risks, including unauthorized data access and user session hijacking for any user who views an infected person record.
Affected Version(s)
laravel-crm 0 <= 2.2.6
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Aaron Amran Bin Amiruddin (@aaronamran)
