S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-25346 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in ChurchCRM affects v. 4.5.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-25346
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter of /churchcrm/v2/family/not-found.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

ChurchCRM is a web-based system designed for religious organizations to manage and track their congregations, donations, events, and communications. It is an open-source platform that offers a range of features to improve the functionality and efficiency of church management. With its user-friendly interface and customizable options, ChurchCRM is an ideal solution for small to medium-sized churches.

However, recently a reflected cross-site scripting (XSS) vulnerability, identified as CVE-2023-25346, was detected in version 4.5.3 of ChurchCRM. This vulnerability arises when an attacker injects malicious code or HTML into the "id" parameter of the "/churchcrm/v2/family/not-found" page. It can potentially allow the attacker to hijack user sessions, modify or steal sensitive data, or even gain unauthorized access to other systems connected to ChurchCRM.

If exploited, this vulnerability can lead to severe security breaches, loss of confidential data, and damage to the reputation of religious organizations who use ChurchCRM. Moreover, it can cause disruption to the smooth functioning of the church and hinder its ability to serve its congregants.

In conclusion, digital assets are a vital part of modern-day church functioning and require regular attention to secure them from potential cyber threats. With the pro features of s4e.io, church administrators and IT staff can stay informed about the latest vulnerabilities and take necessary measures proactively to keep their systems and congregants safe. By taking necessary precautions and staying up-to-date with the latest security trends, churches can maintain a secure and robust digital presence for their congregations and the wider community.

 

REFERENCES

Solution Advice

To protect against this vulnerability, churches can take several precautions, such as:

  • Regularly updating ChurchCRM to the latest version
  • Using a web application firewall (WAF) to monitor and filter out malicious traffic
  • Implementing security headers to restrict the injection of untrusted data
  • Providing security awareness training to all staff to identify and respond to potential security threats
  • Conducting regular vulnerability scans and penetration testing to identify and address vulnerabilities proactively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.