VDB
Sign up
HIGH8.5

GHSA-fpx9-9hq8-w2xc

Webkul Krayin CRM has Server-Side Request Forgery (SSRF)

Details

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/krayin/laravel-crm
Introduced in: 0

No fixed version published yet for krayin/laravel-crm (composer). Pin to a known-safe version or switch to an alternative.

References