Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-64493
HistoryJun 30, 2023 - 12:00 a.m.

ChurchCRM Cross-Site Scripting Vulnerability (CNVD-2023-64493)

2023-06-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
5
churchcrm
cross-site scripting
vulnerability
open source
crm
filtering
escaping
user-supplied data
attacker
web script
html

0.001 Low

EPSS

Percentile

20.6%

ChurchCRM is an open source CRM system for churches. Church CRM version v4.5.3 suffers from a cross-site scripting vulnerability that stems from the application’s lack of effective filtering and escaping of user-supplied data, which can be exploited by an attacker to execute arbitrary Web script or HTML by injecting a crafted payload.

CPENameOperatorVersion
churchcrm churchcrm veq4.5.3

0.001 Low

EPSS

Percentile

20.6%

Related for CNVD-2023-64493