CVE-2026-100882
Received Received - Intake

Cross-Site Scripting in Krayin Laravel-CRM

Vulnerability report for CVE-2026-100882, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulDB

Description

A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
krayin laravel-crm to 2.2.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in Krayin laravel-crm versions up to 2.2.5. It exists in the Admin Settings Endpoint file where manipulating the argument general.settings.footer.label allows remote attackers to inject malicious scripts. The issue is triggered via a manipulated input and can be exploited remotely.

Detection Guidance

To detect this vulnerability, inspect the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php for any modifications to the general.settings.footer.label argument. Check for unusual JavaScript code or unexpected input handling in the footer label section.

Impact Analysis

An attacker could exploit this to execute arbitrary scripts in a user's browser, potentially stealing session cookies, redirecting users to malicious sites, or performing actions on behalf of the user. This could lead to unauthorized access or data theft if the user has elevated privileges.

Compliance Impact

This XSS vulnerability could compromise data confidentiality and integrity, violating GDPR's requirement for protecting personal data and HIPAA's safeguards for protected health information. Organizations may face compliance violations if user data is exposed due to this flaw.

Mitigation Strategies

Upgrade Krayin laravel-crm to version 2.2.6 or later. Apply the patch 6dbcf75b30dbd169ee81b7e9e00368099124efeb to address the cross-site scripting issue in the Admin Settings Endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100882. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart