PT-2024-26488 · Unknown · Campcodes Church Management System

·

CVE-2024-3542

·

Published

2024-04-10

·

Updated

2025-02-19

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Campcodes Church Management System version 1.0
Description A problematic vulnerability was found in the system, affecting unknown code of the file /admin/add visitor.php. The manipulation of the mobile argument leads to cross-site scripting. The attack can be initiated remotely.
Recommendations For version 1.0, consider disabling access to the /admin/add visitor.php file until a patch is available. As a temporary workaround, avoid using the mobile argument in the affected file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-3542

Affected Products

Campcodes Church Management System