Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-26843 PoC — ChurchCRM 跨站脚本漏洞

Source
Associated Vulnerability
Title:ChurchCRM 跨站脚本漏洞 (CVE-2023-26843)
Description:ChurchCRM是一个为教会打造的开源 CRM 系统。 ChurchCRM 4.5.3版本存在安全漏洞。远程攻击者利用该漏洞通过NoteEditor.php注入任意Web脚本或HTML。
Description
A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php.
File Snapshot

id: CVE-2023-26843 info: name: ChurchCRM 4.5.3 - Cross-Site Scripting author: Harsh severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.