Impact
Krayin CRM up to version 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing an attacker to submit a crafted RFC 2822 message and have it stored as an inbound email in the system. The weakness is an authentication bypass (CWE‑306), and the injection permits the sender address, subject, body and header fields to be chosen by the attacker, including reply-to values that could associate the message with an existing conversation thread.
Affected Systems
The vulnerability affects Krayin CRM (Laravel‑CRM) version 2.2.6 and earlier releases. No other products or versions are listed by the CNA.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP POST request to /admin/mail/inbound-parse, which can be performed over the public Internet if the CRM instance is reachable. Successful exploitation would allow an attacker to inject arbitrary emails into the system, compromising the integrity of inbound mail processing.
OpenCVE Enrichment