Krayin CRM 2.2.6 及之前版本存在一个存储型客户端模板注入漏洞,该漏洞允许经过身份验证的攻击者通过在“线索标题”字段中注入 Vue.js 模板表达式,在其他用户的浏览器中执行任意 JavaScript 代码。攻击者可以构造包含双花括号模板语法的线索标题,该内容会被传入 Vue 模板编译器,从而能够进行原型链遍历以获取 Function 构造函数,并在应用程序的上下文中为每个查看受影响的线索记录的用户执行攻击者提供的 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| krayin | laravel-crm | 0 ~ 2.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48543 | 5.4 MEDIUM | Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description |
| CVE-2026-48542 | 5.4 MEDIUM | Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field |
| CVE-2026-48541 | 5.4 MEDIUM | Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field |
No comments yet