Krayin CRM 2.2.6 及之前版本中存在一个存储型客户端模板注入漏洞。该漏洞允许已认证的攻击者通过在产品名称字段中注入 Vue.js 模板表达式,在其他用户的浏览器中执行任意 JavaScript 代码。攻击者可构造包含双花括号模板语法(如 )的产品名称,使其到达 Vue 模板编译器,从而实现原型链遍历以获取 构造函数,进而在应用源上下文中为每个查看受影响产品记录的用户执行攻击者提供的 JavaScript 代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| krayin | laravel-crm | 0 ~ 2.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48543 | 5.4 MEDIUM | Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description |
| CVE-2026-48541 | 5.4 MEDIUM | Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field |
| CVE-2026-48540 | 5.4 MEDIUM | Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title |
No comments yet