PT-2025-30932 · Unknown · Church Donation System

Enigma522

·

Published

2025-07-25

·

Updated

2025-08-05

·

CVE-2025-8167

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Church Donation System version 1.0
Description A vulnerability exists in Church Donation System version 1.0 related to cross site scripting. The issue is located in the /admin/edit members.php file. Manipulation of the fname argument can lead to exploitation. The exploit has been publicly disclosed. Other parameters may also be affected.
Recommendations Address the cross site scripting issue in the /admin/edit members.php file. Sanitize the fname parameter to prevent script injection. Review and sanitize all other parameters used in the affected file.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8167

Affected Products

Church Donation System