描述
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
AI分析AI驱动
受影响产品
webkulkrayin_crm
1.3.0
参考资料
- https://gist.github.com/Tommywarren/89cef7f876ee897a4ff40a8b71b6208eThird Party Advisory