Skip to content

Krayin

v2.2.4 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 3d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

cloud cloudhosting crm crm-multi-tenant-saas crm-platform laravel
+10 more
laravel-application laravel-crm laravel-framework laravel-package opensource opensource-crm opensource-crm-framework php vue vuejs

Affected surfaces

auth rbac rce_ssrf breaking_upgrade

Summary

AI summary

Fixed IDOR agent record access control and unrestricted file upload vulnerabilities.

Full changelog
  • #2581 [enhancement] Fixed responsive UI issues when page is zoomed.
  • #2579 [feature] Allow group selection for individual view permission users.
  • #2575 [enhancement] Added previous month's sales update in Kanban view.
  • #2573 [enhancement] Added dashboard support for multiple pipelines.
  • #2572 [enhancement] Added filter by tag option in Contacts > Persons.
  • #2549 [enhancement] Added support tab feature.
  • #2548 [enhancement] Allow search by phone and email when creating a lead.
  • #2544 [enhancement] Added validate skills.
  • #2543 [enhancement] Added Agents Skills folder.
  • #2546 [feature] Quick Attribute now available at lead form.
  • #2545 [feature] Added agent skills functionality.
  • #2590 [fixed] Fixed page does not refresh after creating a record via Quick Add.
  • #2589 [fixed] Fixed Quick Add not working for users with group and individual permissions.
  • #2582 [fixed] Fixed pipeline field visible on public webform.
  • #2571 [fixed] Fixed issue with lead creation.
  • #2570 [fixed] Fixed auto-fill lead email issue.
  • #2567 [fixed] Fixed IDOR agent record access control vulnerability.
  • #2563 [fixed] Fixed Kanban infinite scroll duplicates issue.
  • #2583 [fixed] Fixed SQL injection in rotten lead filter.
  • #2559 [fixed] Fixed agent record access control issue.
  • #2556 [fixed] Fixed installation config save issue.
  • #2550 [fixed] Fixed Kanban infinite scroll duplicates.
  • #2542 [fixed] Fixed stored XSS vulnerability in notes field.
  • #2541 [fixed] Fixed quote description truncation issue.
  • #2539 [fixed] Fixed lost revenue arrow UI issue.
  • #2538 [fixed] Fixed missing translations.
  • #2501 [fixed] Fixed sales owner not saved in organization.
  • #2500 [fixed] Fixed activities date filter range issue.
  • #2479 [fixed] Fixed textarea field not rendered in WebForm.
  • #2471 [fixed] Fixed missing translations for lead won/lost modal.
  • #2420 [fixed] Added missing mega search translations for settings and configurations.
  • #2533 [fixed] Fixed GUI installation issue.
  • #2454 [fixed] Fixed quote description truncation.
  • #2407 [fixed] Fixed missing translations.
  • #2157 [fixed] Fixed auto-fill lead email when creating a lead.
  • #2258 [fixed] Fixed issue with same-as-billing-address field.
  • #2585 [security] Fixed unrestricted file upload vulnerability.
  • #2419 [security] Fixed stored XSS vulnerability in notes field.

Security Fixes

  • Fixed IDOR agent record access control vulnerability (CVE not provided)
  • Fixed unrestricted file upload vulnerability (CVE not provided)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Krayin

Get notified when new releases ship.

Sign up free

About Krayin

CRM solution for SMEs and Enterprises for complete customer lifecycle management.

All releases →

Related context

Beta — feedback welcome: [email protected]