7.8
CVSSv3

CVE-2023-25348

Published: 25/04/2023 Updated: 28/04/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

ChurchCRM 4.5.3 exists to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow malicious users to execute arbitrary code via a crafted excel file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

churchcrm churchcrm 4.5.3