Vulnerability CVE-2023-38766


Published: 2023-08-08

Description:
Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonView.php component.

 References:
https://github.com/0x72303074/CVE-Disclosures
https://demo.churchcrm.io/master
https://churchcrm.io/
https://github.com/ChurchCRM/CRM/wiki

Copyright 2026, cxsecurity.com

 

Back to Top