Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in ChurchCRM - CVE-2026-39344
Published: May 5, 2026
ChurchCRM
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of script-related HTML tags in the login page username parameter handling in begin-session.php when rendering the login page with a user-supplied username query parameter. A remote attacker can send a specially crafted link to execute arbitrary script in the victim's browser.
User interaction is required to open a crafted login page URL.