PT-2026-98262 · Unknown · Krayin Crm
CVE-2026-48541
·
Published
2026-09-24
·
Updated
2026-09-29
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Krayin CRM versions prior to 2.2.7
Description
Authenticated attackers can execute arbitrary JavaScript in other users' browsers via stored client-side template injection. This occurs when Vue.js template expressions, using double-brace syntax, are injected into the person name field or the web form description field. The input reaches the Vue template compiler, allowing prototype chain traversal to retrieve the Function constructor and execute malicious code in the application origin for any user viewing the affected person record or web form.
Recommendations
Update Krayin CRM to version 2.2.7 or later.
As a temporary mitigation, restrict the use of the person name and web form description fields to trusted users only.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Krayin Crm