Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-10-20T00:00:00

Updated: 2024-09-12T14:47:39.078Z

Reserved: 2023-10-09T00:00:00

Link: CVE-2023-45394

cve-icon Vulnrichment

Updated: 2024-08-02T20:21:16.207Z

cve-icon NVD

Status : Analyzed

Published: 2023-10-20T04:15:10.237

Modified: 2023-10-30T15:29:24.470

Link: CVE-2023-45394

cve-icon Redhat

No data.