A stored cross-site scripting (XSS)... CVE-2023-25347

- AV AC AU C I A
发布: 2023-04-25
修订: 2025-02-04

A stored cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3, allows remote attackers to inject arbitrary web script or HTML via input fields. These input fields are located in the "Title" Input Field in EventEditor.php.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息