CVE-2023-44915
the affected product
A cross-site scripting (XSS) vulnerability in the component /Login.php of c3crm up to v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the login_error parameter.
- CVSS
- 7.1
- EPSS
- 0.27% 19.4% percentile
- CISA KEV
- Not listed
- Published
- 2025.06.26