Executive brief
Krayin CRM, an open-source customer relationship management platform, contains a security flaw that allows any logged-in user to view, modify, or delete records belonging to other users. This includes sensitive business data such as leads, contact information, organizational details, and quotes. An attacker could use this to disrupt business operations, steal customer data, or reassign ownership of sales opportunities to themselves.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in Krayin CRM through version 2.2.3 due to missing record-level ownership validation. The flaw is located within the edit, update, and destroy methods of several controllers, including LeadController, PersonController, OrganizationController, QuoteController, and ActivityController. An authenticated attacker can exploit this by manipulating object identifiers in network requests to access or modify CRM records they do not own. This allows for unauthorized data modification, deletion, and ownership reassignment. A patch has been proposed in the project's GitHub repository to implement proper authorization checks.
Affected products
- Krayin Krayin CRM through 2.2.3
Timeline
- 2026-07-06: patched: Fix proposed in GitHub pull request 2567
- 2026-07-10: disclosed: Initial disclosure and NVD publication