Evidence used
- No CISA KEV confirmation is currently recorded.
- A structured source references public exploit or proof-of-concept material.
- EPSS is 0.48% for the current model date.
BlackTreeCVE IntelligenceKrayin · laravel-crm
Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.
Medium technical severity with public exploit material referenced by a structured source; prioritise exposed affected systems while verifying vendor guidance.
Patch availableA vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
CISA Vulnrichment records proof-of-concept exploitation in its SSVC data. BlackTree has not independently executed or validated exploit material.
CWE-99: Improper Control of Resource Identifiers ('Resource Injection'). The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:PCommon Vulnerability Scoring System 4.0: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 27 Sept 2026 · Last source change 28 Sept 2026, 12:54 UTC · CWE-99 · Improper Control of Resource Identifiers ('Resource Injection')
Core structured fields are present and their contributing authorities are shown above.