NA

CVE-2023-25440

Published: 23/05/2023 Updated: 30/05/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows malicious users to execute arbitrary code in first/second name field.

Vulnerable Product Search on Vulmon Subscribe to Product

civicrm civicrm 5.59

Vendor Advisories

Debian Bug report logs - #1036695 civicrm: CVE-2023-25440 Package: src:civicrm; Maintainer for src:civicrm is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 24 May 2023 12:51:02 UTC Severity: important Tags: security, upstream Reply or subscribe to this bug Tog ...

Exploits

CiviCRM version 559alpha1 suffers from a persistent cross site scripting vulnerability ...