logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-25895

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-25895

Description:
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php
Last updated date:
03/17/2025
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/17/2025
Reference url to background

https://github.com/ChurchCRM/CRM/issues/6853

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy