CVE-2025-0981 - CVE House
Back to Database
Status published High CVE-2025-0981

Session Hijacking via Stored Cross-Site Scripting (XSS) in ChurchCRM GroupEditor.php Description Field

Vulnerability Description

A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to hijack a user's session by exploiting a Stored Cross Site Scripting (XSS) vulnerability in the Group Editor page. This allows admin users to inject malicious JavaScript in the description field, which captures the session cookie of authenticated users. The cookie can then be sent to an external server, enabling session hijacking. It can also lead to information disclosure, as exposed session cookies can be used to impersonate users and gain unauthorised access to sensitive information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-0981

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Michael McInerney

Affected Vendor

Affected Software

ChurchCRM
Vulnerable Versions:
ChurchCRM 5.13.0 and prior

Timeline

Official Publish: February 18th, 2025
Last Modified: February 19th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)