Medium severity5.4NVD Advisory· Published Aug 8, 2023· Updated Jun 17, 2026
CVE-2023-38766
CVE-2023-38766
Description
Cross Site Scripting (XSS) vulnerability in ChurchCRM v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted payload to the PersonView.php component.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- churchcrm.ionvdProduct
- demo.churchcrm.io/masternvdBroken Link
News mentions
0No linked articles in our index yet.