6.5
CVSSv3

CVE-2023-26841

Published: 25/04/2023 Updated: 28/04/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows malicious users to change any user's password except for the user that is currently logged in.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

churchcrm churchcrm 4.5.3