PT-2026-20912 · Churchcrm · Churchcrm
Shingleskat
·
Publicado
2026-02-19
·
Atualizado
2026-02-23
·
CVE-2026-26059
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 6.8.2
Description
ChurchCRM is an open-source church management system. An authenticated user with permission to edit groups could store a JavaScript payload that would execute when the group was viewed in the Group View. The
Group View is the affected component. Version 6.8.2 resolves this issue.Recommendations
Update to version 6.8.2 or later.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Churchcrm