Sceawere
Vulnerability Detail
CVE-2026-100884UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Krayin Laravel-CRM IDOR Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 9h ago
- Vendor
- Krayin
- Product
- laravel-crm
- Attack Type
- Improper Control of Resource Identifiers
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-27T23:16:58.663Z",
"pubdate": "2026-09-27T23:16:58.663Z",
"executiveSummary": "An improper control of resource identifiers vulnerability exists within the Krayin laravel-crm platform, specifically impacting the attachment-download functionality. This vulnerability, categorized as an Insecure Direct Object Reference (IDOR), allows an unauthenticated or authenticated remote attacker to access restricted files or sensitive attachments by manipulating resource IDs within the request.\nThe flaw resides in the Storage::download implementation. By supplying arbitrary identifiers, an attacker can bypass authorization controls that are expected to validate the requestor's ownership or access rights to the target resource. Successful exploitation can lead to unauthorized information disclosure, potentially exposing sensitive business documents, personally identifiable information, or internal configuration files stored on the server.\nGiven that the exploit details are publicly disclosed and the attack can be initiated remotely without complex prerequisites, the risk level is high. The vulnerability affects all versions of Krayin laravel-crm up to and including 2.2.5. Organizations are advised to prioritize updating to version 2.2.6 to remediate the underlying flaw.",
"technicalDetails": "The vulnerability is located in the attachment-download endpoint, specifically within the Storage::download function. The core issue stems from an Insecure Direct Object Reference (IDOR) flaw, where the application fails to implement robust server-side authorization checks when processing file download requests.\nThe application relies on user-supplied input—specifically an ID argument—to locate and retrieve files from storage. Because the controller logic processes this input without validating whether the current user session has the requisite privileges or ownership rights to access the specific file ID provided, the system blindly proceeds with the file retrieval operation.\nThe attack flow begins when an adversary identifies a target resource identifier. Due to the lack of proper validation, the attacker can systematically iterate through ID sequences or utilize known IDs to request unauthorized files. When a request is sent to the attachment-download endpoint with a manipulated ID, the underlying Laravel Storage::download function performs a lookup. If the server-side logic does not compare the requested resource ID against a session-bound permission list or verify ACLs before invocation, it will serve the file directly to the response stream.\nThis vulnerability is exacerbated by the reliance on predictable or discoverable resource identifiers, which are often indexed in the database. An attacker does not require high-level administrative privileges to execute this exploit; the lack of authorization controls creates a bypass scenario where a low-privileged user or even an unauthenticated actor can access files intended for other users or system-internal entities.\nThe impact of this post-exploitation behavior is significant. By manipulating the ID parameter, an attacker can exfiltrate sensitive attachments, potentially leading to a broader breach of data confidentiality. Since the patch identifier 13d6988cda8d69ece45ee1890effc90a7f21cdc1 introduces the necessary logic to enforce authorization and validate identifier ownership, versions prior to 2.2.6 remain fundamentally insecure against this class of IDOR-based information disclosure.\nThe file packages/Webkul/Admin/src/Config/acl.php, while referenced in the context of the affected component, suggests that the intended ACL structure was either improperly referenced, bypassed during the request lifecycle, or incorrectly implemented for the specific download routine, failing to gate-keep the Storage::download execution."
}