PT-2026-57273 · Unknown · Krayin Crm
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Krayin CRM versions prior to 2.2.4
Description
An insecure direct object reference issue exists where authenticated users can edit, update, or delete records belonging to other users. This occurs due to missing record-level ownership validation within the
edit(), update(), and destroy() methods of the following controllers: LeadController, PersonController, OrganizationController, QuoteController, and ActivityController. An attacker can exploit this to modify CRM records and reassign ownership.Recommendations
Update Krayin CRM to version 2.2.4 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Krayin Crm