CVE-2026-100884 | Krayin laravel-crm up to 2.2.5 attachment-download Endpoint acl.php Storage::download ID resource injection (Issue 2624)
A vulnerability marked as problematic has been reported in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers.
This vulnerability is listed as CVE-2026-100884. The attack may be initiated remotely. In addition, an exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More