Reflected Cross-Site Scripting in ChurchCRM by ChurchCRM
CVE-2025-1024
8.4HIGH
What is CVE-2025-1024?
A vulnerability found in ChurchCRM 5.13.0 permits attackers to exploit the application through Reflected Cross-Site Scripting (XSS) on the EditEventAttendees.php page. With Administration privileges, the attacker can manipulate the EID parameter, leading to arbitrary JavaScript execution in a victim's browser. This exploit can facilitate the theft of session cookies, allow unauthorized actions under the guise of an authenticated user, and compromise the security of the application. It is crucial for users to be aware of these risks and update to a safe version.
Affected Version(s)
ChurchCRM ChurchCRM 5.13.0 and prior