PT-2025-30932 · Unknown · Church Donation System

·

CVE-2025-8167

·

Published

2025-07-25

·

Updated

2025-08-05

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Church Donation System version 1.0
Description A vulnerability exists in Church Donation System version 1.0 related to cross site scripting. The issue is located in the /admin/edit members.php file. Manipulation of the fname argument can lead to exploitation. The exploit has been publicly disclosed. Other parameters may also be affected.
Recommendations Address the cross site scripting issue in the /admin/edit members.php file. Sanitize the fname parameter to prevent script injection. Review and sanitize all other parameters used in the affected file.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8167

Affected Products

Church Donation System