CVE-2024-25895
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web
A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php.
MEDIUM · CVSS 6.1
EPSS 0.00107
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0