VDB
Sign up
HIGH8.1

GHSA-32px-ccfx-cxq3

Krayin CRM allows a remote attacker to execute arbitrary code via compose email function

Quick fix

GHSA-32px-ccfx-cxq3 — krayin/laravel-crm: upgrade to the fixed version with the command below.

composer require krayin/laravel-crm:^2.1.6

Details

An issue in Krayin CRM v.2.1.5, which was fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/krayin/laravel-crm
Introduced in: 2.1.5Fixed in: 2.1.6
Fixcomposer require krayin/laravel-crm:^2.1.6

References