EIP-2026-112223
PRE-CVESmall CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-112223. PoCs published by Ghuliev.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Small CRM 3.0 by injecting a JavaScript payload into the 'description' field of a ticket creation form. The payload is executed when the ticket is viewed, allowing arbitrary script execution in the context of the user's session.
Description
Small CRM 3.0 - 'description' Stored Cross-Site Scripting (XSS)
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in Small CRM 3.0 by injecting a JavaScript payload into the 'description' field of a ticket creation form. The payload is executed when the ticket is viewed, allowing arbitrary script execution in the context of the user's session.