CyberRota Analysis
AI-GeneratedKrayin CRM versions up to 2.2.6 are vulnerable due to an unauthenticated exposure of the POST /admin/mail/inbound-parse endpoint, enabling attackers to inject arbitrary emails into the CRM inbox. This flaw allows for the manipulation of email content, including forged sender information and replies to existing threads, potentially leading to data integrity issues and phishing attacks. Organizations using Krayin CRM should prioritize patching this vulnerability to safeguard against unauthorized email injections.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conversation threads.