Stored Cross Site Scripting Vulnerability in CiviCRM by CiviCRM
CVE-2023-25440

5.4MEDIUM

Key Information:

Vendor

Civicrm

Status
Vendor
CVE Published:
23 May 2023

What is CVE-2023-25440?

A Stored Cross Site Scripting vulnerability exists in CiviCRM 5.59.alpha1, specifically within the add contact feature. This flaw allows attackers to inject malicious scripts via the first and second name fields, which then execute in the context of users interacting with the compromised data. If exploited, this vulnerability poses a significant risk, enabling unauthorized execution of arbitrary code and potential data compromise for any user viewing or interacting with the affected component.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.