Reflected XSS Vulnerability in ChurchCRM by ChurchCRM
CVE-2024-25895

Currently unrated

Key Information:

Vendor

ChurchCRM

Status
Vendor
CVE Published:
21 February 2024

What is CVE-2024-25895?

A reflected cross-site scripting vulnerability exists in ChurchCRM 5.5.0, which enables remote attackers to inject arbitrary web scripts or HTML through the 'type' parameter within the '/EventAttendance.php' page. This vulnerability can be exploited to execute malicious scripts in the context of the user's browser, potentially leading to data theft or unauthorized actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.