CVE-2025-0981 – ChurchCRM Stored Cross Site Scripting (XSS) Sessions Hijacking

The following table lists the changes that have been made to the
CVE-2025-0981 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by b7efe717-a805-47cf-8e9a-921fca0ce0ce

    Feb. 18, 2025

    Action Type Old Value New Value
    Added Description A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user’s session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:H/SC:H/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:L/U:Amber
    Added CWE CWE-287
    Added Reference https://github.com/ChurchCRM/CRM/issues/7245
Share the Post:

Related Posts