Reflected XSS Vulnerability in ChurchCRM by ChurchCRM
CVE-2024-25895

Currently unrated

Key Information:

Vendor

ChurchCRM

Status
Vendor
CVE Published:
21 February 2024

What is CVE-2024-25895?

A reflected cross-site scripting vulnerability exists in ChurchCRM 5.5.0, which enables remote attackers to inject arbitrary web scripts or HTML through the 'type' parameter within the '/EventAttendance.php' page. This vulnerability can be exploited to execute malicious scripts in the context of the user's browser, potentially leading to data theft or unauthorized actions.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.