A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
References
Link Resource
https://github.com/Kartikhunter/CVE/blob/main/CVE-2023-43331 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-09-26T00:00:00

Updated: 2023-09-26T21:51:33.862429

Reserved: 2023-09-18T00:00:00


Link: CVE-2023-43331

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-27T15:19:34.003

Modified: 2023-09-29T16:29:51.383


Link: CVE-2023-43331

JSON object: View

cve-icon Redhat Information

No data.

CWE