在 Krayin laravel-crm 最高至 2.2.5 版本中发现了一个漏洞。受影响的元素是 packages/Webkul/Admin/src/Config/acl.php 文件中组件 attachment-download Endpoint 的 Storage::download 函数。对参数 ID 的操纵会导致资源标识符控制不当。攻击可以从远程发起。该漏洞的利用方法已向公众公开,且可能被利用。升级到版本 2.2.6 即可解决此问题。补丁的标识符为 13d6988cda8d69ece45ee1890eff
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Krayin | laravel-crm | 2.2.0 |
cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100885 | 7.3 HIGH | Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization |
| CVE-2026-100883 | 6.3 MEDIUM | Krayin laravel-crm acl.php access control |
| CVE-2026-100882 | 2.4 LOW | Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting |
No comments yet