CVE-2023-24203

MEDIUM

Simple Customer Relationship Management System 1.0 - Cross-Site Scripting via Company or Query Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-24203. PoCs published by momo1239.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-24203, a stored XSS vulnerability in SourceCodester Simple CRM v1.0, including root cause analysis, exploit payloads, and mitigation strategies.

Description

Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

Exploits (1)

nomisec WRITEUP
by momo1239 · poc
https://github.com/momo1239/CVE-2023-24203-and-CVE-2023-24204

This repository provides a detailed technical analysis of CVE-2023-24203, a stored XSS vulnerability in SourceCodester Simple CRM v1.0, including root cause analysis, exploit payloads, and mitigation strategies.

Classification
Writeup 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: SourceCodester Simple Customer Relationship Management (CRM) System v1.0
No auth needed
Prerequisites: Access to the quote request form in the CRM system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 5.4
EPSS 0.0061
EPSS Percentile 44.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
oretnom23/simple_customer_relationship_management_system 1.0
Published May 14, 2024
Tracked Since Feb 18, 2026