CPE
An authentication bypass vulnerability in Krayin CRM version 2.2.6 and earlier allows unauthenticated attackers to inject arbitrary, forged email messages into the CRM inbox via the /admin/mail/inbound-parse endpoint.