{ "id": "CVE-2023-26843", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-25T13:15:10.063", "lastModified": "2023-04-25T15:57:53.957", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "A stored Cross-site scripting (XSS) vulnerability in ChurchCRM 4.5.3 allows remote attackers to inject arbitrary web script or HTML via the NoteEditor.php." } ], "metrics": {}, "references": [ { "url": "https://github.com/10splayaSec/CVE-Disclosures/tree/main/ChurchCRM/CVE-2023-26843", "source": "cve@mitre.org" }, { "url": "https://github.com/ChurchCRM/CRM", "source": "cve@mitre.org" } ] }