CVE-2023-25440: XSS
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25440?
CVE-2023-25440 is a high severity vulnerability due to its potential to enable arbitrary code execution through stored cross-site scripting.
How do I fix CVE-2023-25440?
To fix CVE-2023-25440, upgrade CiviCRM to a version higher than 5.59.alpha1 where this vulnerability has been resolved.
Who is affected by CVE-2023-25440?
CVE-2023-25440 affects users of CiviCRM version 5.59.alpha1.
What kind of attacks can be executed with CVE-2023-25440?
Attackers can execute arbitrary JavaScript code through the first and second name fields in the add contact function due to CVE-2023-25440.
Is there a workaround for CVE-2023-25440?
Currently, the best workaround for CVE-2023-25440 is to avoid using the affected version of CiviCRM until it can be upgraded.