VDB
Sign up
MEDIUM5.4

GHSA-j822-46r5-h4qx

Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint

Quick fix

GHSA-j822-46r5-h4qx — krayin/laravel-crm: upgrade to the fixed version with the command below.

composer require krayin/laravel-crm:^2.1.6

Details

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/krayin/laravel-crm
Introduced in: 2.1.5Fixed in: 2.1.6
Fixcomposer require krayin/laravel-crm:^2.1.6

References