Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Upgrading to version 2.2.6 is able to resolve this issue. The identifier of the patch is b9836530ec9f5ef0f51653bb0cbbc47ef7184f51. It is advisable to upgrade the affected component. | |
| Title | krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting | |
| First Time appeared |
Krayin
Krayin laravel-crm |
|
| Weaknesses | CWE-79 CWE-94 |
|
| CPEs | cpe:2.3:a:krayin:laravel-crm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Krayin
Krayin laravel-crm |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-25T18:30:19.532Z
Reserved: 2026-09-25T10:05:26.998Z
Link: CVE-2026-97896
No data.
Status : Received
Published: 2026-09-25T19:17:59.967
Modified: 2026-09-25T19:17:59.967
Link: CVE-2026-97896
No data.
OpenCVE Enrichment
No data.