Splendid CRM suffers from a persistent cross site scripting vulnerability.
f3ec24f1b0f8a6f48890014674c1fdd67559525020cc9f604e6360fa1ef742aa
#Description : Splendid CRM Software, Inc. (open source crm)
#vendor:http: http://demo.splendidcrm.com/
#author:provensec
#type:stored xss
#exploit:
1 Goto contact edit page for example
http://demo.splendidcrm.com/Contacts/edit.aspx?ID=cb4bb68f-0233-41b3-87cb-2c6469a29f16
2 Edit the first name field with xss payload <body/onload=alert(1) ==>
http://prntscr.com/4lg1d6 screenshot
3 Save it and javascript will execute