Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component. | |
| Title | Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting | |
| First Time appeared |
Krayin
Krayin laravel-crm |
|
| Weaknesses | CWE-79 CWE-94 |
|
| CPEs | cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Krayin
Krayin laravel-crm |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-27T22:00:13.969Z
Reserved: 2026-09-27T03:43:54.754Z
Link: CVE-2026-100882
No data.
Status : Received
Published: 2026-09-27T22:17:06.123
Modified: 2026-09-27T22:17:06.123
Link: CVE-2026-100882
No data.
OpenCVE Enrichment
No data.