CVE-2026-97896 | krayin laravel-crm up to 2.2.5 Upload Functionality ConfigurationForm.php ConfigurationForm::rules cross site scripting (Issue 2617)

SecurityVulns

A vulnerability, which was classified as problematic, has been found in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. The manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-97896. The attack is possible to be carried out remotely. Moreover, an exploit is present.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More