Webkul Krayin CRM是印度Webkul公司的一款客户关系管理系统。 Webkul Krayin CRM 2.2.4版本存在授权问题漏洞,该漏洞源于安装程序中间件缺少身份验证,导致未经身份验证的远程攻击者可通过构造带有X-Requested-With: XMLHttpRequest头的HTTP POST请求绕过CanInstall中间件重定向检查,向admin-config-setup端点提供任意姓名、邮箱和密码值,覆盖主管理员账户,从而获取所有CRM数据的完全管理访问权限。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| krayin | laravel-crm | ≤ 2.2.0 |
affected |
2.2.1≤ 2.2.3 |
unaffected | ||
2.2.4 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| krayin | laravel-crm | 0 ~ 2.2.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41452.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC暂无评论