mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-02 07:51:39 +02:00
18 lines
688 B
Markdown
18 lines
688 B
Markdown
### [CVE-2020-28849](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28849)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/ChurchCRM/CRM/issues/5477
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|