Impact
A stored Cross‑Site Scripting flaw exists in the Note Editor of ChurchCRM. An authenticated user with permission to add notes can embed malicious JavaScript into a note, which is displayed in the profile of any user who views that note. The injected code executes with the privileges of the viewing user, enabling attackers to steal session cookies, elevate themselves to administrator level, or access confidential member data. This weakness aligns with CWE‑79."
Affected Systems
ChurchCRM versions 6.5.2 and earlier are affected. All installations of the open‑source ChurchCRM product before the release of 6.5.3 contain the vulnerable Note Editor. No other vendors are impacted.
Risk and Exploitability
The CVSS severity score of 7.3 indicates a high level of risk. Exploitation requires a legitimate authenticated user with note‑adding permissions; the attacker must place the malicious payload in a note that another user will read. Upon execution in the victim’s browser, the script can hijack sessions and execute privileged actions. While no public exploits are currently known and the issue is not listed in the KEV catalog, the simplicity of the attack and the serious potential impact warrant treating the vulnerability as an immediate threat.
OpenCVE Enrichment