CVE-2026-39333
🟡 Monitoruj
Odbicie XSS w ChurchCRM pozwala na wykonanie dowolnego JavaScriptu przez uwierzytelnionego użytkownika.
CVSS
8.7
EPSS
0.0%
Exploit
none
Vendor
churchcrm
Opis źródłowy (NVD)
ChurchCRM is an open-source church management system. Prior to 7.1.0, he FindFundRaiser.php endpoint reflects user-supplied input (DateStart and DateEnd) into HTML input field attributes without proper output encoding for the HTML attribute context. An authenticated attacker can craft a malicious URL that executes arbitrary JavaScript when visited by another authenticated user. This constitutes a reflected XSS vulnerability. This vulnerability is fixed in 7.1.0.
xss
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.7 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.0% |
| Opublikowano (NVD) | 2026-04-07 18:16:44 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-10 20:57:56 UTC |
Referencje
- https://github.com/ChurchCRM/CRM/security/advisories/GHSA-fqq6-qrcf-h7h5 (security-advisories@github.com) [Third Party Advisory]