CVE-2023-24203
MEDIUMSimple Customer Relationship Management System 1.0 - Cross-Site Scripting via Company or Query Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-24203. PoCs published by momo1239.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-24203, a stored XSS vulnerability in SourceCodester Simple CRM v1.0, including root cause analysis, exploit payloads, and mitigation strategies.
Description
Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).
Exploits (1)
nomisec
WRITEUP
by momo1239 · poc
https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204
This repository provides a detailed technical analysis of CVE-2023-24203, a stored XSS vulnerability in SourceCodester Simple CRM v1.0, including root cause analysis, exploit payloads, and mitigation strategies.
Classification
Writeup 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
SourceCodester Simple Customer Relationship Management (CRM) System v1.0
No auth needed
Prerequisites:
Access to the quote request form in the CRM system
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
References (3)
Core 3
Core References
Exploit, Third Party Advisory
https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204
URL Repurposed
https://momonguyen.com/2023/cve-2023-24203/
Product
https://www.sourcecodester.com
Scores
CVSS v3
5.4
EPSS
0.0061
EPSS Percentile
44.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
oretnom23/simple_customer_relationship_management_system
1.0
Published
May 14, 2024
Tracked Since
Feb 18, 2026