A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript in the description field, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/ChurchCRM/CRM/issues/7245 |
![]() ![]() |
History
Fri, 21 Feb 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Churchcrm
Churchcrm churchcrm |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Churchcrm
Churchcrm churchcrm |
|
Metrics |
cvssV3_1
|
Wed, 19 Feb 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information. | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript in the description field, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information. |
Title | Session Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM Group Editor | Session Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM GroupEditor.php Description Field |
Tue, 18 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 18 Feb 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information. | |
Title | Session Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM Group Editor | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Gridware
Published:
Updated: 2025-02-19T08:37:46.688Z
Reserved: 2025-02-03T10:22:18.062Z
Link: CVE-2025-0981

Updated: 2025-02-18T14:29:32.328Z

Status : Analyzed
Published: 2025-02-18T10:15:10.333
Modified: 2025-02-21T15:23:43.717
Link: CVE-2025-0981

No data.