CVE-2020-28848: Churchcrm

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

CSV Injection vulnerability in ChurchCRM version 4.2.0, allows remote attackers to execute arbitrary code via crafted CSV file.

Affected products

Published 2023-08-11. Last modified 2026-06-17.