Cross Site Scripting Vulnerability in Krayin Laravel CRM by Krayin
CVE-2026-97897
5.1MEDIUM
What is CVE-2026-97897?
A security flaw has been identified in Krayin's Laravel CRM, affecting versions up to 2.2.5, where the TinyMCE Media Upload component's Sanitizer.php file is susceptible to a cross-site scripting attack. This vulnerability can be leveraged by an attacker via remote exploitation, potentially compromising user data. Affected users are strongly encouraged to update to version 2.2.6 or later, which addresses this issue with a patch identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345, to ensure the security of their systems.
Affected Version(s)
laravel-crm 2.2.0
laravel-crm 2.2.1
laravel-crm 2.2.2
