CVE-2025-67876 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows…
Critical CVSS: 9.3

CVE-2025-67876

ChurchCRM is an open-source church management system. A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM versions 6.4.0 and prior that allows a low-privilege user with the “Manage Groups” permission to inject persistent JavaScript into group role names. The payload is saved in the database and executed whenever any user (including administrators) views a page that displays that role, such as GroupView.php or PersonView.php. This allows full session hijacking and account takeover. As of time of publication, no known patched versions are available.
Vendor
Churchcrm
Product
Churchcrm
CWE
CWE-79
Yayın Tarihi
2025-12-17 22:16:00
Güncelleme
2025-12-18 18:30:45
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar