CVE Feed

    Dashboard / CVE / CVE-2026-41453

    CVE-2026-41453

    Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.

    Published:Aug 3, 2026
    Last Modified:Aug 14, 2026
    EPS:Aug 3, 2026
    EPSS Score:0.0035
    CVSS Score:8.8

    Affected Products

    Vendor
    Krayin
    Product
    Laravel-crm
    Vendor
    Webkul
    Product
    Krayin Crm

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High