PT-2026-98262 · Unknown · Krayin Crm

CVE-2026-48541

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Krayin CRM versions prior to 2.2.7
Description Authenticated attackers can execute arbitrary JavaScript in other users' browsers via stored client-side template injection. This occurs when Vue.js template expressions, using double-brace syntax, are injected into the person name field or the web form description field. The input reaches the Vue template compiler, allowing prototype chain traversal to retrieve the Function constructor and execute malicious code in the application origin for any user viewing the affected person record or web form.
Recommendations Update Krayin CRM to version 2.2.7 or later. As a temporary mitigation, restrict the use of the person name and web form description fields to trusted users only.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48541

Affected Products

Krayin Crm