Cross-site scripting in ChurchCRM - #VU142441

 

Cross-site scripting in ChurchCRM - #VU142441

Published: August 13, 2026


Vulnerability identifier: #VU142441
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in an administrator\'s session.

The vulnerability exists due to improper neutralization of input during web page generation in GroupView.js render callbacks for group member fields when concatenating escapeHtml output into tel:, mailto:, and data-name attributes. A remote user can store a specially crafted cell phone, email, or full name value to execute arbitrary script in an administrator\'s session.

User interaction is required when the victim opens the affected group view, and the proven exploit variant triggers on hover.


Affected software

ChurchCRM

Remediation

Install security update from vendor's website.

ChurchCRM - update to 7.6.0

External References

Related Security Bulletins