Cross-site scripting in ChurchCRM - #VU142441
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in an administrator\'s session.
The vulnerability exists due to improper neutralization of input during web page generation in GroupView.js render callbacks for group member fields when concatenating escapeHtml output into tel:, mailto:, and data-name attributes. A remote user can store a specially crafted cell phone, email, or full name value to execute arbitrary script in an administrator\'s session.
User interaction is required when the victim opens the affected group view, and the proven exploit variant triggers on hover.