Krayin CRM是Krayin CRM组织的一款客户关系管理系统。 Krayin CRM 2.2.4之前版本存在SQL注入漏洞,该漏洞源于在leads DataGrid中,通过操作rotten_lead[in]查询参数,未使用参数化绑定直接连接到LeadDataGrid.php中的havingRaw()调用,可能导致具有leads访问权限的认证用户利用基于时间和布尔型的盲注技术提取整个数据库内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| krayin | laravel-crm | < 2.2.4 |
affected |
2.2.4 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| krayin | laravel-crm | 0 ~ 2.2.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
VULNERABLE: blind SQLi via rotten_lead[in] HAVING clause extracted proof token "PROOF_93c3a09238b12f10" from DB (time-based SLEEP delay 2.10s also confirmed)
No comments yet