Junglewise Threat Intelligence

CVE-2026-36748: Spark Development Network RockRMS XSS in user profile social media links

CVE-2026-36748 · Severity: info · Published 2026-06-03

Executive brief

RockRMS, a popular church management system, contains a security flaw in how it handles social media links on user profiles. An attacker can insert malicious scripts into these links, which then run in the browser of other users, such as administrators, who view the profile. This could allow an attacker to hijack sessions or gain unauthorized administrative access to the organization's data and operations.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in RockRMS versions 16.13 through 17.7.0. The flaw is located in the user profile component, specifically within the fields used for social media links, which fail to properly sanitize user-supplied input. An authenticated attacker can inject malicious JavaScript into their own profile; when a victim (such as a high-privileged administrator) views the affected profile, the script executes in the context of the victim's session. According to researcher reports, this can be leveraged for privilege escalation. Users should update to version 17.7.0 or later to mitigate this risk.

Affected products

  • Spark Development Network RockRMS v16.13 and before v17.7.0

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References