CVE-2025-1597
A vulnerability was found in SourceCodester Best Church Management Software 1.0.
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/redirect.php. The manipulation of the argument a leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-94
- Affected
- mayurik/best church management software
- Source
- cna@vuldb.com
References
- https://github.com/xiahao90/CVEproject/blob/main/xiahao.webray.com.cn/best-church-management-software-xss.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.296592Permissions Required, VDB Entry
- https://vuldb.com/?id.296592Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.497883Third Party Advisory, VDB Entry
- https://www.sourcecodester.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.