5.3
CVSSv3

CVE-2023-26840

Published: 25/04/2023 Updated: 28/04/2023
CVSS v3 Base Score: 5.3 | Impact Score: 3.6 | Exploitability Score: 1.6
VMScore: 0

Vulnerability Summary

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to set a person to a user and set that user to be an Administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

churchcrm churchcrm 4.5.3