Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-26842 PoC — ChurchCRM 跨站脚本漏洞

Source
Associated Vulnerability
Title:ChurchCRM 跨站脚本漏洞 (CVE-2023-26842)
Description:ChurchCRM是一个为教会打造的开源 CRM 系统。 ChurchCRM 4.5.3版本存在安全漏洞,该漏洞源于存在存储型跨站脚本(XSS)漏洞,允许远程攻击者通过OptionManager.php注入任意Web脚本或HTML。
Description
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the OptionManager.php.
File Snapshot

id: CVE-2023-26842 info: name: ChurchCRM 4.5.3 - Cross-Site Scripting author: Harsh severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.