Medium severity5.4NVD Advisory· Published Jan 26, 2023· Updated Jun 17, 2026
CVE-2022-47073
CVE-2022-47073
Description
A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.
Affected products
4- cpe:2.3:a:small_crm_project:small_crm:3.0:*:*:*:*:*:*:*
- Small CRM/Small CRMdescription
- Range: = 3.0
Patches
Vulnerability mechanics
References
2- packetstormsecurity.comnvdThird Party AdvisoryVDB Entry
- medium.com/%40shiva.infocop/stored-xss-found-in-small-crm-phpgurukul-7890ea3c04dfnvd
News mentions
0No linked articles in our index yet.