CVE-2024-45932
published 2024-10-07CVE-2024-45932: Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
PriorityP417medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
EPSS
0.42%
35.9th percentile
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| krayin | laravel-crm | 0 – 1.3.0 | — |
| webkul | krayin_crm | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
ghsa·2024-10-07
CVE-2024-45932 [MEDIUM] CWE-79 Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in `/admin/contacts/organizations/edit/2`.
OSV
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
osv·2024-10-07
CVE-2024-45932 [MEDIUM] Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in `/admin/contacts/organizations/edit/2`.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-07
Published