A vulnerability described as problematic has been identified in ChurchCRM up to 7.0.x. This affects the function sanitizeText of the file PersonView.php of the component HTML Attribute Handler. Such manipulation of the argument Facebook leads to HTML injection. The attack may be performed from remote.
| Vendor | Product | Versions |
|---|---|---|
| churchcrm | crm | < 7.1.0, < 7.0.0 |
Updated description with new details, changed affected versions to < 7.0.0, and updated severity to MEDIUM.
Initial creation