CVE-2026-5370 Details
Description
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch.
A stored cross-site scripting vulnerability has been identified in Krayin Laravel CRM versions up to 2.2. The issue resides in the Activities Module/Notes Module, specifically within the 'composeMail' function of the 'packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts' file. This vulnerability allows for the injection of malicious JavaScript that is executed when the content is viewed by other users, including administrators. The problem stems from improper handling of user input in the Notes field, which accepted and rendered unsafe HTML, CSS, and JavaScript. The vulnerability can be exploited remotely, and a public exploit is available.
Users are advised to update to the latest version of Krayin Laravel CRM, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 2, 2026CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/krayin/laravel-crm/ | [email protected] | Vendor |
| https://github.com/krayin/laravel-crm/commit/73ed28d466bf14787fdb86a120c656a4af270153 | [email protected] | Source CodeVendor |
| https://github.com/krayin/laravel-crm/issues/2419 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/krayin/laravel-crm/pull/2466 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/submit/781666 | [email protected] | Technical Description |
| https://vuldb.com/vuln/354756 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/vuln/354756/cti | [email protected] | AdvisoryContent Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| krayin laravel-crm | <= 2.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Apr 2, 2026 | New CVE Received | [email protected] |
Volerion