Reflected Cross-Site Scripting in ChurchCRM by ChurchCRM
CVE-2025-1024
8.4HIGH
Key Information:
- Vendor
- Churchcrm
- Status
- Churchcrm
- Vendor
- CVE Published:
- 19 February 2025
Summary
A vulnerability found in ChurchCRM 5.13.0 permits attackers to exploit the application through Reflected Cross-Site Scripting (XSS) on the EditEventAttendees.php page. With Administration privileges, the attacker can manipulate the EID parameter, leading to arbitrary JavaScript execution in a victim's browser. This exploit can facilitate the theft of session cookies, allow unauthorized actions under the guise of an authenticated user, and compromise the security of the application. It is crucial for users to be aware of these risks and update to a safe version.
Affected Version(s)
ChurchCRM ChurchCRM 5.13.0 and prior
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael McInerney