2023-08-11 16:00:35 +00:00
{
"id" : "CVE-2020-28849" ,
"sourceIdentifier" : "cve@mitre.org" ,
"published" : "2023-08-11T14:15:11.237" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T05:23:11.563" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-08-11 16:00:35 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module."
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "Una vulnerabilidad de Cross-Site Scripting (XSS) en ChurchCRM v4.2.1 permite a atacantes remotos ejecutar c\u00f3digo arbitrario y obtener informaci\u00f3n confidencial a trav\u00e9s de un payload manipulado en el campo \"Add New Deposit\" del m\u00f3dulo \"View All Deposit\". "
2023-08-11 16:00:35 +00:00
}
] ,
2023-08-17 02:00:33 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM" ,
2023-08-17 02:00:33 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-08-17 02:00:33 +00:00
} ,
"exploitabilityScore" : 2.3 ,
"impactScore" : 2.7
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-79"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "4.2.1" ,
"matchCriteriaId" : "2B81A55D-F3F1-4217-BAED-3DC4A7F24DF9"
}
]
}
]
}
] ,
2023-08-11 16:00:35 +00:00
"references" : [
{
"url" : "https://github.com/ChurchCRM/CRM/issues/5477" ,
2023-08-17 02:00:33 +00:00
"source" : "cve@mitre.org" ,
"tags" : [
"Exploit" ,
"Issue Tracking"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://github.com/ChurchCRM/CRM/issues/5477" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Exploit" ,
"Issue Tracking"
]
2023-08-11 16:00:35 +00:00
}
]
}