PT-2026-5408 · Churchcrm · Churchcrm

Sonntb21Dcat164

·

Publicado

2026-01-30

·

Atualizado

2026-02-17

·

CVE-2026-24855

CVSS v4.0

8.5

Alta

VetorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.7.2
Description ChurchCRM, an open-source church management system, contains a Stored Cross-Site Scripting (XSS) issue in the Create Events feature within the Church Calendar. A user with limited privileges can inject malicious code into the Description field. This code is then saved to the database and executed when other users, including administrators, view the event. This can lead to account compromise.
Recommendations Update to ChurchCRM version 6.7.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24855
GHSA-49QP-CFQX-C767

Produtos afetados

Churchcrm