CVE-2024-45932: XSS
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
Other sources
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45932?
The severity of CVE-2024-45932 is classified as high due to its potential to allow Cross Site Scripting (XSS) attacks.
How do I fix CVE-2024-45932?
To fix CVE-2024-45932, sanitize and validate the input in the organization name field to prevent XSS attacks.
What versions of Krayin CRM are affected by CVE-2024-45932?
Krayin CRM v1.3.0 is the only affected version by CVE-2024-45932.
What kind of attack does CVE-2024-45932 enable?
CVE-2024-45932 enables Cross Site Scripting (XSS) attacks through manipulation of the organization name field.
Where is the vulnerability CVE-2024-45932 found in Krayin CRM?
CVE-2024-45932 is found in the organization name field on the /admin/contacts/organizations/edit/2 page.