Stored Cross-Site Scripting in ChurchCRM Affects User Data Security
CVE-2025-68401
What is CVE-2025-68401?
ChurchCRM, an open-source church management system, suffers from a stored Cross-Site Scripting (XSS) vulnerability allowing the execution of attacker-controlled JavaScript. The application prior to version 6.0.0 inadequately sanitizes and encodes user-supplied HTML/JS. If a user submits malicious content, any subsequent view by other users can lead to the execution of this script in their browsers. This exploitation can access sensitive information, such as web origin data, and may even perform privileged actions on behalf of the victim. Particularly concerning is the risk of session theft, especially when session cookies are not marked HttpOnly, as it opens avenues for account takeover. Version 6.0.0 addresses and mitigates this vulnerability.
Affected Version(s)
CRM < 6.0.0
