Webkul Krayin CRM是印度Webkul公司的一款客户关系管理系统。 Webkul Krayin CRM 2.2.4版本存在授权问题漏洞,该漏洞源于安装程序中间件缺少身份验证,导致未经身份验证的远程攻击者可通过构造带有X-Requested-With: XMLHttpRequest头的HTTP POST请求绕过CanInstall中间件重定向检查,向admin-config-setup端点提供任意姓名、邮箱和密码值,覆盖主管理员账户,从而获取所有CRM数据的完全管理访问权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| krayin | laravel-crm | ≤ 2.2.0 |
affected |
2.2.1≤ 2.2.3 |
unaffected | ||
2.2.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| krayin | laravel-crm | 0 ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware caused by bypassing the CanInstall middleware redirect check via crafted HTTP POST requests, letting unauthenticated remote attackers overwrite the primary administrator account and gain full administrative access, exploit requires crafted HTTP POST with specific header. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-41452.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet