First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andy Moyle Church Admin allows Stored XSS.This issue affects Church Admin: from n/a through 4.1.17.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Andy Moyle Church Admin | <=4.1.17 | |
WordPress Church Admin plugin | <=4.1.17 |
Update to 4.1.18 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30193 is classified as a critical severity vulnerability due to its potential for Stored Cross-Site Scripting (XSS).
To fix CVE-2024-30193, update Andy Moyle Church Admin to the latest version beyond 4.1.17, or apply patches as provided by the vendor.
CVE-2024-30193 can allow attackers to inject malicious scripts into web pages viewed by users, leading to data theft and unauthorized actions.
CVE-2024-30193 affects Andy Moyle Church Admin versions up to and including 4.1.17.
CVE-2024-30193, involving Stored XSS, is a common type of vulnerability that can exist in web applications if user input is not properly validated.