Cross Site Scripting Vulnerability in ChurchCRM Web Application
CVE-2023-38761
6.1MEDIUM
What is CVE-2023-38761?
A Cross Site Scripting (XSS) vulnerability exists in ChurchCRM version 5.0.0, which can allow a remote attacker to execute arbitrary code. This is achieved through a specially crafted payload targeting the systemSettings.php component, potentially compromising the integrity and security of the application. For more information, visit the official ChurchCRM website.