{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-5325","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-04-01T13:15:18.142Z","datePublished":"2026-04-02T07:00:19.365Z","dateUpdated":"2026-04-02T13:35:08.601Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-04-02T07:00:19.365Z"},"title":"SourceCodester Simple Customer Relationship Management System Create Ticket create-ticket.php cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"Cross Site Scripting"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-94","lang":"en","description":"Code Injection"}]}],"affected":[{"vendor":"SourceCodester","product":"Simple Customer Relationship Management System","versions":[{"version":"1.0","status":"affected"}],"modules":["Create Ticket"]}],"descriptions":[{"lang":"en","value":"A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create Ticket. This manipulation of the argument Description causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.1,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-04-01T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-04-01T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-04-01T15:20:22.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"Hemant Raj Bhati (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/354656","name":"VDB-354656 | SourceCodester Simple Customer Relationship Management System Create Ticket create-ticket.php cross site scripting","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/354656/cti","name":"VDB-354656 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/submit/780766","name":"Submit #780766 | SourceCodester Simple Customer Relationship Management (CRM) System 1.0 Cross Site Scripting","tags":["third-party-advisory"]},{"url":"https://medium.com/@hemantrajbhati5555/stored-cross-site-scripting-xss-in-simple-customer-relationship-management-system-crm-php-15a904589844","tags":["broken-link","exploit"]},{"url":"https://www.sourcecodester.com/","tags":["product"]}],"tags":["x_freeware"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-04-02T13:34:56.788873Z","id":"CVE-2026-5325","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-04-02T13:35:08.601Z"}}]}}