S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-26843 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in ChurchCRM affects v. 4.5.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-26843
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

ChurchCRM is a popular open-source Customer Relationship Management (CRM) platform designed to cater to the unique needs of religious organizations. This product is built to simplify and automate the church's day-to-day operations and help manage member and donor relationships. The ChurchCRM platform provides churches with a suite of tools for member tracking and communication, event management, and online giving.

However, the platform has been discovered with a severe vulnerability, CVE-2023-26843, which puts users' data at risk of being compromised. The flaw is a stored Cross-site scripting (XSS) vulnerability, which allows malicious actors to inject arbitrary web script or HTML via the NoteEditor.php. This type of vulnerability is prevalent and can allow attackers to take over user accounts, steal sensitive data, or even spread malware.

If this vulnerability is exploited, it can lead to serious consequences for the church organizations that use ChurchCRM. Attackers can use this vulnerability to steal sensitive data, including personal information, billing information, financial reports, and member records. This information can then be used for identity theft, financial fraud, or blackmailing purposes, which can have severe consequences for the affected organizations and their members.

In conclusion, with the pro features of the s4e.io platform, individuals and organizations can easily and quickly learn about vulnerabilities in their digital assets. s4e.io enables you to conduct automated, continuous security testing, and identify vulnerabilities, compliance gaps, and more. By utilizing this platform, individuals and organizations can proactively secure themselves and stay ahead of attackers who are constantly seeking to exploit vulnerabilities.

 

REFERENCES

Solution Advice

To protect against this vulnerability in ChurchCRM, a few essential precautions can be taken. These include:

  • Keeping the platform updated and patched with the latest security updates.
  • Enabling content security policies (CSP) to prevent cross-site scripting attacks.
  • Implementing input validation and sanitization techniques to filter malicious inputs.
  • Implementing a web application firewall (WAF) to block malicious traffic.
  • Educating users to be vigilant and aware of phishing and other social engineering attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.