CVE-2023-45394: Small CRM Project Small CRM
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
Affected products
- Small CRM Project Small CRM: version 3.0 only
Published 2023-10-20. Last modified 2026-06-17.