


Perceptive Security
SOC/SIEM Consultancy

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 18:04:46
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Database & Storage
Krayin CRM versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid component. The flaw exists in LeadDataGrid.php where the rotten_lead[in] query parameter is concatenated without parameterized binding directly into a havingRaw() call. Authenticated users with leads access can exploit this vulnerability to inject arbitrary SQL into a HAVING clause. Attackers can leverage time-based and boolean-based blind injection techniques to extract sensitive data. Exploitable data includes user credential hashes, CRM records, and application configuration data. The vulnerability requires authentication but does not require administrative privileges. A patch has been released in version 2.2.4 of Krayin CRM. The fix is available via a commit on the official GitHub repository.
Technical details
Mitigation steps:
Affected products:
Krayin CRM
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41453
https://github.com/krayin/laravel-crm/commit/2a3724cb7e9e65ab98f2b42c8ca2c98dede48f62
https://github.com/krayin/laravel-crm/releases/tag/v2.2.4
https://jivasecurity.com/writeups/krayin-lead-datagrid-sqli-cve-2026-41453
https://www.vulncheck.com/advisories/krayin-crm-blind-sql-injection-via-leaddatagrid-php-rotten-lead-parameter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
