{ "id": "CVE-2023-26840", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-25T13:15:09.987", "lastModified": "2023-04-25T15:57:53.957", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "A cross-site request forgery (CSRF) vulnerability in ChurchCRM v4.5.3 allows attackers to set a person to a user and set that user to be an Administrator." } ], "metrics": {}, "references": [ { "url": "https://github.com/10splayaSec/CVE-Disclosures/tree/main/ChurchCRM/CVE-2023-26840", "source": "cve@mitre.org" }, { "url": "https://github.com/ChurchCRM/CRM", "source": "cve@mitre.org" } ] }