First published: Tue May 23 2023(Updated: )
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CiviCRM | =5.59-alpha1 | |
=5.59-alpha1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25440 is a high severity vulnerability due to its potential to enable arbitrary code execution through stored cross-site scripting.
To fix CVE-2023-25440, upgrade CiviCRM to a version higher than 5.59.alpha1 where this vulnerability has been resolved.
CVE-2023-25440 affects users of CiviCRM version 5.59.alpha1.
Attackers can execute arbitrary JavaScript code through the first and second name fields in the add contact function due to CVE-2023-25440.
Currently, the best workaround for CVE-2023-25440 is to avoid using the affected version of CiviCRM until it can be upgraded.