CVE-2023-24203

MEDIUM

SourceCodester CRM 1.0 - XSS

Title source: llm
STIX 2.1

Description

Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

Exploits (1)

nomisec WRITEUP
by momo1239 · poc
https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204

References (3)

Core 3

Scores

CVSS v3 5.4
EPSS 0.0029
EPSS Percentile 52.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
oretnom23/simple_customer_relationship_management_system 1.0
Published May 14, 2024
Tracked Since Feb 18, 2026