在 Krayin laravel-crm 2.2.4 及更早版本中发现了一个漏洞。该漏洞影响的是 admin-config-setup API 端点中文件 packages/Webkul/Installer/src/Http/Middleware/CanInstall.php 的某个未知函数。由于对该函数的操纵,可导致授权绕过。攻击者可以远程发起攻击。该漏洞的利用代码已被公开,可供使用。升级至版本 2.2.5 可缓解此问题。相关补丁标识为 89f2916b6a46ff91bd1999ce38158fa0de8b94
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Krayin | laravel-crm | 2.2.0 |
cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100883 | 6.3 MEDIUM | Krayin laravel-crm acl.php access control |
| CVE-2026-100884 | 4.3 MEDIUM | Krayin laravel-crm attachment-download Endpoint acl.php resource injection |
| CVE-2026-100882 | 2.4 LOW | Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting |
No comments yet