top of page
perceptive_background_267k.jpg

ChurchCRM is an open-source church management system. Prior to 7.0.0, a stored cross-site scripting (XSS) vulnerability exists in ChurchCRM within the Person Pr…

Published:

6 april 2026 om 22:00:00

Alert date:

7 april 2026 om 19:08:14

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

ChurchCRM, an open-source church management system, contains a stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.0. The vulnerability exists in the Person Property Management subsystem and allows authenticated users to inject arbitrary JavaScript code via dynamically assigned person properties. This issue persists even in versions patched for CVE-2023-38766. The malicious payload is stored persistently and executes when other users view affected person profiles or access printable views, potentially leading to session hijacking or full account compromise. The vulnerability has been fixed in version 7.0.0.

Technical details

Mitigation steps:

Affected products:

ChurchCRM

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page