5.4
CVSSv3

CVE-2023-45394

Published: 20/10/2023 Updated: 30/10/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an malicious user to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.

Vulnerable Product Search on Vulmon Subscribe to Product

small crm project small crm 3.0