Vendor
Blind SQL Injection in Krayin CRM leads DataGrid
1 rule 1 TTP 1 CVEKrayin CRM versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid, allowing authenticated attackers to exfiltrate database contents via the rotten_lead[in] query parameter.
Krayin CRM Installer Authentication Bypass Vulnerability
1 rule 1 TTP 1 CVEKrayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.
Krayin CRM Insecure Direct Object Reference Vulnerability (CVE-2026-61460)
3 TTPs 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-61460, in Krayin CRM through version 2.2.3 allows authenticated users to modify, update, or delete records owned by other users by exploiting missing record-level ownership validation in various controllers, leading to unauthorized data manipulation.
Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit
1 TTPA public exploit (EDB-52629) has been released for Krayin CRM v2.2.x, demonstrating an authenticated remote code execution vulnerability that allows an authenticated attacker to execute arbitrary code on the underlying system, significantly increasing the risk for unpatched deployments of the web application.