Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Insecure Direct Object Reference (IDOR) in Krayin CRM 2.2.4 Allows Unauthenticated Data Access

Krayin CRM version 2.2.4 contains an IDOR flaw that permits unauthenticated retrieval of arbitrary customer records via manipulated object IDs. The issue highlights the need for robust object‑level access controls and continuous control‑assurance evidence when handling SaaS applications. Organizations should verify they are not running the vulnerable version and document remediation for audit readiness.

LiveThreat™ Intelligence · 📅 October 02, 2026· 📰 exploit-db.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
exploit-db.com

Insecure Direct Object Reference (IDOR) in Krayin CRM 2.2.4 Allows Unauthenticated Data Access

What Happened — Krayin CRM version 2.2.4 contains an Insecure Direct Object Reference (IDOR) flaw. An attacker can change a record identifier in a request and retrieve arbitrary customer records without authentication. Exploit‑DB published a proof‑of‑concept that demonstrates the issue.

Why It Matters for Trust & Control Assurance

  • The vulnerability exposes a gap in object‑level access controls, a control‑mapping objective that continuous assurance programs are built to monitor.
  • Remediation evidence (patches, version inventories, test results) becomes part of a defensible audit trail.
  • Demonstrating that you have identified and closed such gaps satisfies multiple framework mappings through a single VCF control objective.

Who Is Affected — SaaS CRM vendors, their enterprise customers, and any organization that runs Krayin CRM 2.2.4 (across all verticals).

Recommended Actions — Verify the deployed Krayin CRM version; upgrade to a patched release or apply the vendor’s mitigation. Conduct a focused penetration test on object‑reference endpoints, and record remediation steps as evidence for audit readiness. Source: https://www.exploit-db.com/exploits/52687

Technical Notes — The IDOR is triggered via API calls such as GET /api/v1/records/{id} where the {id} parameter is not validated against the requester’s permissions. No CVE identifier has been assigned yet. Exposed data includes contact details, sales opportunities, and other CRM records. Source: https://www.exploit-db.com/exploits/52687

📰 Original Source
https://www.exploit-db.com/exploits/52687 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →