Vulnerability Description
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Churchcrm | Churchcrm | 4.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/10splayaSec/CVE-Disclosures/tree/main/ChurchCRM/CVE-2023-2534ExploitThird Party Advisory
- https://github.com/ChurchCRM/CRMProduct
- https://github.com/10splayaSec/CVE-Disclosures/tree/main/ChurchCRM/CVE-2023-2534ExploitThird Party Advisory
- https://github.com/ChurchCRM/CRMProduct
FAQ
What is CVE-2023-25348?
CVE-2023-25348 is a vulnerability with a CVSS score of 7.8 (HIGH). ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbit...
How severe is CVE-2023-25348?
CVE-2023-25348 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-25348?
Check the references section above for vendor advisories and patch information. Affected products include: Churchcrm Churchcrm.