Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Churchcrm | Churchcrm | 4.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/10splayaSec/CVE-Disclosures/tree/main/ChurchCRM/CVE-2023-2534ExploitThird Party Advisory
- https://github.com/ChurchCRM/CRMProduct
- https://github.com/10splayaSec/CVE-Disclosures/tree/main/ChurchCRM/CVE-2023-2534ExploitThird Party Advisory
- https://github.com/ChurchCRM/CRMProduct
FAQ
What is CVE-2023-25347?
CVE-2023-25347 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Inp...
How severe is CVE-2023-25347?
CVE-2023-25347 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25347?
Check the references section above for vendor advisories and patch information. Affected products include: Churchcrm Churchcrm.