PT-2025-6818 · Churchcrm · Churchcrm
Michael Mcinerney
+1
·
Published
2025-02-18
·
Updated
2025-02-19
·
CVE-2025-0981
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/AU:Y/R:U/V:C/RE:L/U:Amber |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions 5.13.0 and prior
Description
A Stored Cross Site Scripting (XSS) vulnerability exists in the Group Editor page, allowing attackers to hijack user sessions. Admin users can inject malicious JavaScript in the description field, capturing the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking and potentially leading to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorized access to sensitive information.
Recommendations
For ChurchCRM versions 5.13.0 and prior, consider disabling the Group Editor page or restricting access to it until a patch is available. As a temporary workaround, avoid using the description field in the Group Editor page to prevent malicious JavaScript injection. Restrict access to sensitive information and monitor user activity for potential session hijacking attempts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Churchcrm