A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. This requires Administration privileges and affects the EID parameter. The flaw allows an attacker to steal session cookies, perform actions on behalf of an authenticated user, and gain unauthorized access to the application.
History

Tue, 25 Feb 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Churchcrm
Churchcrm churchcrm
Weaknesses CWE-79
CPEs cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*
Vendors & Products Churchcrm
Churchcrm churchcrm
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Wed, 19 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Feb 2025 08:45:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in ChurchCRM 5.13.0 that allows an attacker to execute arbitrary JavaScript in a victim's browser via Reflected Cross-Site Scripting (XSS) in the EditEventAttendees.php page. This requires Administration privileges and affects the EID parameter. The flaw allows an attacker to steal session cookies, perform actions on behalf of an authenticated user, and gain unauthorized access to the application.
Title Session Hijacking via Reflected Cross-Site Scripting (XSS) in ChurchCRM EditEventAttendees.php EID Parameter
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/AU:Y/R:U/V:C/RE:L/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published:

Updated: 2025-02-19T19:40:43.255Z

Reserved: 2025-02-04T10:31:53.126Z

Link: CVE-2025-1024

cve-icon Vulnrichment

Updated: 2025-02-19T19:40:31.852Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-19T09:15:10.280

Modified: 2025-02-25T21:50:07.637

Link: CVE-2025-1024

cve-icon Redhat

No data.