Krayin CRM 2.2.6 版本存在一个漏洞: 端点未在认证状态下暴露,使得未经身份验证的攻击者能够将任意电子邮件注入 CRM 收件箱。攻击者可以发送经过构造的符合 RFC 2822 规范的邮件,其中包含伪造的发件人信息和标头,从而插入具有任意主题和正文的邮件,甚至可以作为现有会话线程的回复进行插入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| krayin | laravel-crm | ≤ 2.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| krayin | laravel-crm | 0 ~ 2.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet