CVE-2023-33661 | ChurchCRM 4.5.3 GroupReports.php GroupRole/ReportModel/OnlyCart cross site scripting (Issue 6474 / EUVD-2023-37817)
A vulnerability marked as problematic has been reported in ChurchCRM 4.5.3. Affected is an unknown function of the file GroupReports.php. The manipulation of the argument GroupRole/ReportModel/OnlyCart leads to cross site scripting.
This vulnerability is traded as CVE-2023-33661. It is possible to initiate the attack remotely. There is no exploit available.