PT-2026-99720 · Unknown · Krayin Laravel-Crm
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Krayin laravel-crm versions prior to 2.2.6
Description
Cross site scripting occurs in the Admin Settings Endpoint within the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php. A remote attacker can trigger this issue by manipulating the
general.settings.footer.label argument.Recommendations
Upgrade to version 2.2.6.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Krayin Laravel-Crm