Insecure Direct Object Reference (IDOR) in Krayin CRM 2.2.4 Allows Unauthenticated Data Access
What Happened — Krayin CRM version 2.2.4 contains an Insecure Direct Object Reference (IDOR) flaw. An attacker can change a record identifier in a request and retrieve arbitrary customer records without authentication. Exploit‑DB published a proof‑of‑concept that demonstrates the issue.
Why It Matters for Trust & Control Assurance
- The vulnerability exposes a gap in object‑level access controls, a control‑mapping objective that continuous assurance programs are built to monitor.
- Remediation evidence (patches, version inventories, test results) becomes part of a defensible audit trail.
- Demonstrating that you have identified and closed such gaps satisfies multiple framework mappings through a single VCF control objective.
Who Is Affected — SaaS CRM vendors, their enterprise customers, and any organization that runs Krayin CRM 2.2.4 (across all verticals).
Recommended Actions — Verify the deployed Krayin CRM version; upgrade to a patched release or apply the vendor’s mitigation. Conduct a focused penetration test on object‑reference endpoints, and record remediation steps as evidence for audit readiness. Source: https://www.exploit-db.com/exploits/52687
Technical Notes — The IDOR is triggered via API calls such as GET /api/v1/records/{id} where the {id} parameter is not validated against the requester’s permissions. No CVE identifier has been assigned yet. Exposed data includes contact details, sales opportunities, and other CRM records. Source: https://www.exploit-db.com/exploits/52687