PT-2023-19742 · Churchcrm · Churchcrm

Blakduk

·

Published

2023-02-09

·

Updated

2025-03-24

·

CVE-2023-24690

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions 4.5.3 and below
Description A stored cross-site scripting (XSS) issue was found in the /api/public/register/family API endpoint. This could potentially allow attackers to inject malicious scripts into the application.
Recommendations For ChurchCRM versions 4.5.3 and below, update to a version above 4.5.3 to resolve the issue. As a temporary workaround, consider restricting access to the /api/public/register/family API endpoint until a patch is available. Avoid using this endpoint in applications where user input is not properly sanitized.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-24690

Affected Products

Churchcrm