ZeroHour

CVE-2023-45394

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p29
Published
()
Modified
Description

Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.

Vendors
small crm project
Products
small crm
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.