<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Krayin CRM (2.2.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/krayin-crm-2.2.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 03 Aug 2026 18:05:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/krayin-crm-2.2.4/feed.xml" rel="self" type="application/rss+xml"/><item><title>Krayin CRM Installer Authentication Bypass Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-08-krayin-auth-bypass/</link><pubDate>Mon, 03 Aug 2026 18:05:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-krayin-auth-bypass/</guid><description>Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.</description><content:encoded><![CDATA[<p>Krayin CRM version 2.2.4 is affected by a critical missing authentication vulnerability (CVE-2026-41452) located within the installer middleware. An unauthenticated remote attacker can bypass the CanInstall middleware redirect by including a specific HTTP header, 'X-Requested-With: XMLHttpRequest', in a POST request directed at the application's configuration endpoint. This flaw permits the attacker to interact with the 'admin-config-setup' endpoint, which contains an 'updateOrInsert' function targeting the hardcoded primary administrator user ID. By submitting arbitrary name, email, and password values, an attacker can overwrite existing administrator credentials, resulting in full administrative compromise of the CRM instance. This vulnerability is of high concern due to the ease of exploitation and the potential for full data access and administrative control over the target CRM environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to gain full administrative access to Krayin CRM instances. This grants the attacker unrestricted access to all stored CRM data, including customer records, sales information, and communications, as well as the ability to modify system settings or further persist within the environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately restrict access to the CRM installer endpoints using network-level controls until the vendor releases a security update for Krayin CRM 2.2.4.</li>
<li>Audit access logs for unauthorized HTTP POST requests directed to the 'admin-config-setup' URI path, specifically looking for requests containing the 'X-Requested-With: XMLHttpRequest' header originating from unauthorized IP addresses.</li>
<li>Review administrative user accounts for anomalous changes or unknown credentials that may indicate post-exploitation account takeover.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>crm</category><category>authentication-bypass</category></item></channel></rss>