Popis
ChurchCRM is an open-source church management system. Prior to 7.1.0, a stored cross-site scripting vulnerability exists in ChurchCRM-s person profile editing functionality. Non-administrative users who have the EditSelf permission can inject malicious JavaScript into their Facebook, LinkedIn, and X profile fields. Due to a 50-character field limit, the payload is distributed across all three fields and chains their onfocus event handlers to execute in sequence. When any user, including administrators, views the attacker-s profile, their session cookies are exfiltrated to a remote server. This vulnerability is fixed in 7.1.0.
CVSS 8.9EPSS 0.203%Riziko 0.91
Zobraziť zdroj- Zverejnené
- 2026-04-07 18:16:44
- Dotknuté verzie
- <7.1.0
- Typ
- Core software
- Vektor
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:L