Home

Description

An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function

PUBLISHED Reserved 2026-04-06 | Published 2026-04-30 | Updated 2026-04-30 | Assigner mitre

References

github.com/cybercrewinc/CVE-2026-36340 exploit

drive.google.com/...d/1yBdvbrXGf9fsFckmK9zTe2v8_vDtdicH/view

github.com/krayin/laravel-crm/releases/tag/v2.1.6

github.com/cybercrewinc/CVE-2026-36340

cve.org (CVE-2026-36340)

nvd.nist.gov (CVE-2026-36340)

Download JSON