Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2xx8-j85v-j7wh

Опубликовано: 14 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.

Пакеты

Наименование

krayin/laravel-crm

composer
Затронутые версииВерсия исправления

<= 2.2.0

Отсутствует

EPSS

Процентиль: 28%
0.00351
Низкий

8.1 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 8.1
nvd
4 месяца назад

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.

EPSS

Процентиль: 28%
0.00351
Низкий

8.1 High

CVSS3

Дефекты

CWE-639