5.4
CVSSv3

CVE-2020-28849

Published: 11/08/2023 Updated: 17/08/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.

Vulnerable Product Search on Vulmon Subscribe to Product

churchcrm churchcrm