Sceawere

Vulnerability Detail

CVE-2026-100882UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Krayin Laravel-CRM XSS Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
2.4
Creation Date
10h ago
Vendor
Krayin
Product
laravel-crm
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "2.4",
  "pubDate": "2026-09-27T22:17:06.123Z",
  "pubdate": "2026-09-27T22:17:06.123Z",
  "executiveSummary": "A Cross-Site Scripting (XSS) vulnerability exists in Krayin laravel-crm up to version 2.2.5 within the Admin Settings component.\nThe vulnerability stems from improper neutralization of user-supplied input provided via the 'general.settings.footer.label' argument.\nSuccessful exploitation allows a remote, unauthenticated or authenticated attacker to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nThe risk implication is significant as it may lead to session hijacking, unauthorized actions on behalf of the administrator, or the exfiltration of sensitive data.\nThe vulnerability is currently publicly disclosed, and exploitation is feasible remotely without specialized physical access to the server infrastructure.\nUsers are strongly advised to upgrade to version 2.2.6 or apply the identified patch 6dbcf75b30dbd169ee81b7e9e00368099124efeb to remediate the flaw.",
  "technicalDetails": "The vulnerability is classified as a Reflected or Stored Cross-Site Scripting (XSS) flaw, depending on how the application persists the 'general.settings.footer.label' configuration value. The root cause lies in the insufficient input sanitization and output encoding within the 'packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php' file.\nIn the Laravel Blade template engine, data rendered directly into the HTML context without proper escaping—or using unescaped syntax such as '{!! !!}' instead of '{{ }}'—renders the application susceptible to injection attacks. The 'general.settings.footer.label' argument is processed by the Admin Settings endpoint and subsequently reflected in the administrative layout without validation.\nThe attack flow proceeds as follows: An attacker identifies the administrative interface configuration functionality where the 'general.settings.footer.label' parameter is exposed. The attacker injects a malicious payload, such as a script tag containing arbitrary JavaScript, into this parameter. Upon submission, the application updates the configuration and stores the payload. When an administrator or a privileged user subsequently loads the affected index page, the browser interprets the injected payload as executable code rather than plain text. This occurs because the application fails to sanitize the input before storage or fails to contextually encode the output upon rendering the footer label.\nThis vulnerability is reachable remotely via the Admin Settings endpoint. Since the payload executes within the victim's browser, the attacker can leverage the victim's session cookies to perform unauthorized administrative actions, capture sensitive CSRF tokens, or manipulate the Document Object Model (DOM) to phish for credentials. The impact is elevated if the attacker targets a user with high privileges, effectively leading to full compromise of the CRM application management interface.\nThe lack of adequate output encoding in the specified Blade component acts as the primary vector for this injection. By failing to strip or escape characters such as '<', '>', '\"', and \"'\", the application permits the breakout of HTML attributes or the insertion of new script tags, thereby bypassing basic security filters that may be present elsewhere in the application."
}
CVE-2026-100882: Krayin Laravel-CRM XSS Vulnerability (LOW Severity, CVSS: 2.4) | Sceawere