Executive brief
Krayin laravel-crm is an open-source customer relationship management system built with Laravel. After installation, the installer component remains accessible and can be exploited by an unauthenticated attacker to take over the super administrator account by simply sending an HTTP header. An attacker can change the admin username, email, and password, gaining complete administrative control of the CRM system.
Technical details
An authentication bypass in the installer middleware (CanInstall.php) allows unauthenticated access to the admin-config-setup API endpoint when the X-Requested-With: XMLHttpRequest header is present. The vulnerable endpoint allows modification of existing administrator credentials without authentication. The fix is available in version 2.2.5 (patch 89f2916b6a46ff91bd1999ce38158fa0de8b9490).
Affected products
- Krayin laravel-crm up to 2.2.4
Timeline
- 2026-09-27: disclosed
- 2026-09-27: patched: Version 2.2.5 released with fix