CVE-2026-38527 Details
Description
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Webkul Krayin CRM version 2.2.x. The issue resides in the webhook creation component, specifically at the endpoint '/settings/webhooks/create'. This vulnerability allows authenticated attackers to send crafted POST requests that the server will forward to internal resources, potentially leading to unauthorized access or information disclosure.
Users are advised to implement a URL allowlist for webhook URLs, rejecting any that point to private IP ranges, loopback addresses, link-local addresses, or cloud metadata endpoints. Additionally, consider using an outgoing request proxy that enforces IP blocklists at the network level.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 14, 2026CISA-ADP
Assessed Apr 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/krayin/laravel-crm | [email protected] | ProductVendor |
| https://github.com/TREXNEGRO/Security-Advisories/tree/main/CVE-2026-38527 | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Webkul Krayin CRM | ~2.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | New CVE Received | [email protected] |
Volerion