Show filters
46 Total Results
Displaying 31-40 of 46
Sort by:
Attacker Value
Unknown

CVE-2023-26841

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to change any user's password except for the user that is currently logged in.
Attacker Value
Unknown

CVE-2023-26840

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administrator.
Attacker Value
Unknown

CVE-2023-26839

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to edit information for existing people on the site.
Attacker Value
Unknown

CVE-2023-25348

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and First Name input fields when creating a new person. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.
Attacker Value
Unknown

CVE-2023-25347

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.
Attacker Value
Unknown

CVE-2023-25346

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.
Attacker Value
Unknown

CVE-2023-26855

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
The hashing algorithm of ChurchCRM v4.5.3 utilizes a non-random salt value which allows attackers to use precomputed hash tables or dictionary attacks to crack the hashed passwords.
Attacker Value
Unknown

CVE-2023-27059

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Group Name text field.
Attacker Value
Unknown

CVE-2023-24690

Disclosure Date: February 09, 2023 (last updated October 08, 2023)
ChurchCRM 4.5.3 and below was discovered to contain a stored cross-site scripting (XSS) vulnerability at /api/public/register/family.
Attacker Value
Unknown

CVE-2023-24686

Disclosure Date: February 09, 2023 (last updated October 08, 2023)
An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.