A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event Sermon field in EventEditor.php.
References
| Link | Resource |
|---|---|
| https://github.com/ChurchCRM/CRM/issues/6851 | Exploit Issue Tracking |
| https://github.com/ChurchCRM/CRM/issues/6851 | Exploit Issue Tracking |
Configurations
History
No history.
Information
Published : 2024-02-21 18:15
Updated : 2025-03-28 17:15
NVD link : CVE-2024-25898
Mitre link : CVE-2024-25898
CVE.ORG link : CVE-2024-25898
JSON object : View
Products Affected
churchcrm
- churchcrm
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
