CVE-2026-100884
LOW
2,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
MEDIUM
4,0
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: none
Availability: none
Description
AI Translation Available
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
99
Improper Control of Resource Identifiers ('Resource Injection')
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Application Data
Modify Application Data
Read Files Or Directories
Modify Files Or Directories
Applicable Platforms
All platforms may be affected
https://github.com/carlosalbertotuma/advisory/blob/main/advisory-06-IDOR-Email-…
https://github.com/krayin/laravel-crm/
https://github.com/krayin/laravel-crm/commit/13d6988cda8d69ece45ee1890effc90a7f…
https://github.com/krayin/laravel-crm/issues/2624
https://github.com/krayin/laravel-crm/pull/2627
https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
https://vuldb.com/cve/CVE-2026-100884
https://vuldb.com/submit/916218
https://vuldb.com/vuln/410814
https://vuldb.com/vuln/410814/cti