Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
churchcrm churchcrm 4.5.3 vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-26839
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to edit information for existing people on the site.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26840
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to set a person to a user and set that user to be an Administrator.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26841
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to change any user's password except for the user that is currently logged in.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26842
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote malicious users to inject arbitrary web script or HTML via the OptionManager.php.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26843
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote malicious users to inject arbitrary web script or HTML via the NoteEditor.php.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-26855
The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows malicious users to use precomputed hash tables or dictionary attacks to crack the hashed passwords.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-27059
A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Group Name text field.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-25346
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote malicious users to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-25347
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote malicious users to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.
Churchcrm Churchcrm 4.5.3
NA
CVE-2023-25348
ChurchCRM 4.5.3 exists to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow malicious users to execute arbitrary code via a crafted excel file.
Churchcrm Churchcrm 4.5.3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »