Executive brief
Webkul Krayin CRM, a customer relationship management platform, contains a security flaw in how it handles lead records. An authorized user of the system can view, modify, or permanently delete sales leads belonging to other users by simply changing the ID number in their browser's address bar. This could lead to the theft of sensitive customer data, loss of sales records, or unauthorized changes to deal statuses.
Technical details
A Broken Object-Level Authorization (BOLA) vulnerability, also known as Insecure Direct Object Reference (IDOR), exists in the LeadController.php of Webkul Krayin CRM v2.2.x. The application fails to perform ownership validation when processing requests for lead objects via the {id} parameter in GET, PUT, and DELETE requests. An authenticated attacker with low privileges can manipulate these IDs to bypass authorization and perform unauthorized CRUD operations on leads owned by other users. The root cause is the lack of a check to ensure the lead's user_id matches the authenticated user's ID or granted permissions. As of the advisory date, a formal patch version has not been confirmed.
Affected products
- Webkul Krayin CRM (laravel-crm) <= 2.2.0
Timeline
- 2026-04-14: advisory: GitHub Advisory published
- 2026-04-14: disclosed: NVD publication date