PT-2026-32682 · Undefined · Undefined
Trexnegro
·
Published
2026-04-14
·
Updated
2026-04-19
·
CVE-2026-38528
CVSS v3.1
7.1
High
| Vector | AC:L/AV:N/A:N/C:H/I:L/PR:L/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions
Krayin CRM versions 2.2.x
Description
SQL injection is possible via the
rotten lead parameter at the '/Lead/LeadDataGrid.php' endpoint. SQL injection is a type of flaw that allows an attacker to interfere with the queries that an application makes to its database.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undefined