A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE.
History

Thu, 26 Jun 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Webkul
Webkul krayin Crm
CPEs cpe:2.3:a:webkul:krayin_crm:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:webkul:krayin_crm:2.1.0:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul krayin Crm

Mon, 14 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Apr 2025 13:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE.
Title Webkul Krayin CRM SVG File edit cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-04-14T13:31:04.358Z

Updated: 2025-04-14T14:00:29.161Z

Reserved: 2025-04-13T23:02:39.883Z

Link: CVE-2025-3568

cve-icon Vulnrichment

Updated: 2025-04-14T13:59:08.299Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-14T14:15:25.630

Modified: 2025-06-26T19:21:05.930

Link: CVE-2025-3568

cve-icon Redhat

No data.