Impact
Krayin CRM through version 2.2.3 allows an authenticated user to edit, update, or delete records that belong to other users. The flaw stems from missing record‑level ownership validation in several controller actions, enabling attackers to directly reference and manipulate objects they should not have access to. This and potential reassigning of ownership, compromising data integrity and confidentiality. The weakness is classified as CWE‑639, which represents an insecure direct object reference where an attacker learns or predicts object identifiers. The impact is limited to authenticated users with sufficient application access but can affect large numbers of records across the system.
Affected Systems
The vulnerability affects the Krayin CRM product, specifically all versions up through 2.2.3. Installations of 2.2.3 or earlier are considered vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been encountered in major exploits. Attackers can exploit the flaw by sending requests to the vulnerable controller endpoints with IDs of records belonging to other users; no special privileges beyond normal authenticated access are required. Organizations that grant broad edit rights or omit ownership checks face a higher risk.
OpenCVE Enrichment