Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
| Software | From | Fixed in |
|---|---|---|
| small_crm_project / small_crm | 3.0 | 3.0.x |