CVE-2026-100882 Details
Description
A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.
A stored cross-site scripting vulnerability has been identified in Krayin CRM versions 2.2.5 and prior. The issue resides in the Admin Settings Endpoint, specifically within the file 'packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php'. The vulnerability arises because the application allows authenticated users with permission to modify system configuration to inject arbitrary HTML into the 'general.settings.footer.label' parameter. Although the TinyMCE editor attempts to sanitize this input, the filtering can be bypassed by sending a direct HTTP request to the server. The injected script is executed whenever an administrator views a page that includes the global footer.
Users are advised to upgrade to Krayin CRM version 2.2.6, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/carlosalbertotuma/advisory/blob/main/advisory-04-stored-xss-via-footer.md | [email protected] | AdvisoryExploitRemedy |
| https://github.com/krayin/laravel-crm/ | [email protected] | ProductSource CodeVendor |
| https://github.com/krayin/laravel-crm/commit/6dbcf75b30dbd169ee81b7e9e00368099124efeb | [email protected] | Source CodeVendor |
| https://github.com/krayin/laravel-crm/issues/2622 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/krayin/laravel-crm/pull/2625 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/krayin/laravel-crm/releases/tag/v2.2.6 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-100882 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/916088 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410812 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/410812/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Krayin | <= 2.2.5 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion