S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-26842 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in ChurchCRM affects v. 4.5.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-26842
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ChurchCRM is an open-source management system designed for churches. It is used to manage various church-related data including members, donations, and groups. With its intuitive interface and robust features, ChurchCRM aims to make managing church-related data easy and efficient. The system's main purpose is to increase church productivity, organization, and enhance overall growth.

However, ChurchCRM 4.5.3 was found to have a stored Cross-site scripting (XSS) vulnerability, coded as CVE-2023-26842. This vulnerability allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php. When exploited, this vulnerability would allow attackers to obtain sensitive information of church members and may even allow them to take over the systems.

This vulnerability can lead to many disastrous consequences when exploited. Attackers can exploit the vulnerability to launch phishing attacks against members of the church. They may also be able to access financial information, medical records, and any other sensitive data that the system may store. In the hands of black-hat hackers, this vulnerability could easily put the entire Church system, its members, and their data at great risk.

In conclusion, s4e.io provides a comprehensive platform where you can learn about vulnerabilities within your digital assets. By taking advantage of their pro features, you can be sure that you will stay ahead of the game and protect against any potential vulnerabilities. Remember that timely updates, modern security measures, and user education can go a long way in protecting your church system and its members from any and all potential threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of ChurchCRM 4.5.3 are advised to take the following precautions:

  • Update to the latest version of the system
  • Disable any unnecessary features in the system
  • Regularly update and maintain the system
  • Monitor the system for any suspicious activity
  • Educate Church members on basic security practices to avoid phishing attacks and data loss.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-26842 scanner - Cross-Site Scripting (XSS) vulnerability in ChurchCRM | S4E