References https://nvd.nist.gov/vuln/detail/CVE-2025-3568 https://access.redhat.com/security/cve/cve-2025-3568 https://github.com/shellkraft/CVE-2025-3568 https://sneharghya.medium.com/how-i-discovered-cve-2025-3568-from-xss-to-admin-account-takeover-6dabfcc7a320 https://security.snyk.io/vuln/SNYK-PHP-KRAYINLARAVELCRM-10343887 https://vuldb.com/vuln/304609 https://cve.imfht.com/detail/CVE-2025-3568?lang=en https://feedly.com/cve/CVE-2025-3568 https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2025-3568 https://cvefeed.io/vuln/product/86534/webkulkrayin_crm/
Related VulnerabilitiesPoCCVE-2026-41452: Krayin CRM < 2.2.1 - Installer Authentication BypassPoCkrayin-installer: Krayin CMS - InstallerPoCCVE-2023-30256: Webkul QloApps 1.5.2 - Cross-site ScriptingPoCCVE-2023-36287: Webkul QloApps 1.6.0 - Cross-site ScriptingPoCCVE-2023-36289: Webkul QloApps 1.6.0 - Cross-site ScriptingWebkul QloApps 1.5.2版本存在xss漏洞(CVE-2023-30256)