Medium severity5.4NVD Advisory· Published May 23, 2023· Updated Jun 17, 2026
CVE-2023-25440
CVE-2023-25440
Description
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/172470/CiviCRM-5.59.alpha1-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB Entry
- civicrm.orgnvdProduct
News mentions
0No linked articles in our index yet.