PT-2025-7485 · Churchcrm · Churchcrm
Michael Mcinerney
+1
·
Published
2025-02-19
·
Updated
2025-02-25
·
CVE-2025-1024
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/AU:Y/R:U/V:C/RE:L/U:Amber |
Name of the Vulnerable Software and Affected Versions
ChurchCRM version 5.13.0
Description
A vulnerability exists in ChurchCRM that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. This requires Administration privileges and affects the
EID parameter. The flaw allows an attacker to steal session cookies, perform actions on behalf of an authenticated user, and gain unauthorized access to the application.Recommendations
For ChurchCRM version 5.13.0, as a temporary workaround, consider disabling access to the EditEventAttendees.php page or restricting the use of the
EID parameter until a patch is available. Avoid using the EID parameter in the affected page to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Authentication
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Churchcrm