Описание
ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the “Manage Groups” permission to inject persistent JavaScript into group role names. The payload is saved in the database and executed whenever any user (including administrators) views a page that displays that role, such as GroupView.php or PersonView.php. This allows full session hijacking and account takeover. As of time of publication, no known patched versions are available.
Ссылки
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 6.4.0 (включая)
cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
EPSS
Процентиль: 10%
0.00035
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79
EPSS
Процентиль: 10%
0.00035
Низкий
5.4 Medium
CVSS3
Дефекты
CWE-79