{"api_version":"1","generated_at":"2026-07-23T12:28:14+00:00","cve":"CVE-2020-28849","urls":{"html":"https://cve.report/CVE-2020-28849","api":"https://cve.report/api/cve/CVE-2020-28849.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-28849","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-28849"},"summary":{"title":"CVE-2020-28849","description":"Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-08-11 14:15:00","updated_at":"2023-08-17 01:55:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/ChurchCRM/CRM/issues/5477","name":"https://github.com/ChurchCRM/CRM/issues/5477","refsource":"MISC","tags":[],"title":"Cross Site Scripting Vulnerability leading to Remote File Inclusion · Issue #5477 · ChurchCRM/CRM · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-28849","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28849","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"28849","vulnerable":"1","versionEndIncluding":"4.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"churchcrm","cpe5":"churchcrm","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-28849","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross Site Scripting (XSS) vulnerability in ChurchCRM version 4.2.1, allows remote attckers to execute arbitrary code and gain sensitive information via crafted payload in Add New Deposit field in View All Deposit module."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/ChurchCRM/CRM/issues/5477","refsource":"MISC","name":"https://github.com/ChurchCRM/CRM/issues/5477"}]}},"nvd":{"publishedDate":"2023-08-11 14:15:00","lastModifiedDate":"2023-08-17 01:55:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:churchcrm:churchcrm:*:*:*:*:*:*:*:*","versionEndIncluding":"4.2.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"28849","Ordinal":"191911","Title":"CVE-2020-28849","CVE":"CVE-2020-28849","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"28849","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}