CVE-2026-5370 | krayin laravel-crm up to 2.2 Activities Module/Notes inbox.spec.ts composeMail cross site scripting (Issue 2419)
A vulnerability identified as problematic has been detected in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-5370. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
To fix this issue, it is recommended to deploy a patch.