PT-2025-6818 · Churchcrm · Churchcrm

Michael Mcinerney

+1

·

Published

2025-02-18

·

Updated

2025-02-19

·

CVE-2025-0981

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/AU:Y/R:U/V:C/RE:L/U:Amber
Name of the Vulnerable Software and Affected Versions ChurchCRM versions 5.13.0 and prior
Description A Stored Cross Site Scripting (XSS) vulnerability exists in the Group Editor page, allowing attackers to hijack user sessions. Admin users can inject malicious JavaScript in the description field, capturing the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking and potentially leading to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorized access to sensitive information.
Recommendations For ChurchCRM versions 5.13.0 and prior, consider disabling the Group Editor page or restricting access to it until a patch is available. As a temporary workaround, avoid using the description field in the Group Editor page to prevent malicious JavaScript injection. Restrict access to sensitive information and monitor user activity for potential session hijacking attempts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0981

Affected Products

Churchcrm