Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Vesp3Rtine

#31102de 53,638
8.3CVSS total
Vulnerabilidades · 1
PT-2025-51870
8.3
2025-12-17
Churchcrm · Churchcrm · CVE-2025-66397
**Name of the Vulnerable Software and Affected Versions** ChurchCRM versions prior to 6.5.3 **Description** ChurchCRM, an open-source church management system, has an issue with access control in the Kiosk Manager feature. Specifically, the `allowRegistration`, `acceptKiosk`, `reloadKiosk`, and `identifyKiosk` functions are affected. Any authenticated user can perform actions such as allowing and accepting kiosk registrations, reloading, and identifying kiosks. **Recommendations** Update to version 6.5.3 or later.