Security Advisory

CVE-2025-68399

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-17 21:40:23
Last updated 2025-12-18 15:08:14
Assigner GitHub_M
CVSS score 2.0
State PUBLISHED

Description

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within the GroupEditor.php page of the application. When a user attempts to create a group role, they can execute malicious JavaScript. However, for this to work, the user must have permission to view and modify groups in the application. Version 6.5.4 fixes the issue.