Required CVE Record Information
Description
An issue in the CSV Import function of ChurchCRM v4.5.3 and below allows attackers to execute arbitrary code via importing a crafted CSV file.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- https://github.com/ChurchCRM/CRM x_transferred
- http://churchcrm.io/ x_transferred
- https://github.com/blakduk/Advisories/blob/main/ChurchCRM/README.md x_transferred