Vulnerabilities
Vulnerable Software
Webkul:  >> Krayin Crm  >> 2.2.0  Security Vulnerabilities
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-04-14
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.
CVSS Score
8.1
EPSS Score
0.0
Published
2026-04-14
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.
CVSS Score
8.1
EPSS Score
0.0
Published
2026-04-14


Contact Us

Shodan ® - All rights reserved