PT-2025-51870 · Churchcrm · Churchcrm

Vesp3Rtine

·

Publicado

2025-12-17

·

Atualizado

2025-12-21

·

CVE-2025-66397

CVSS v3.1

8.3

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, has an issue with access control in the Kiosk Manager feature. Specifically, the allowRegistration, acceptKiosk, reloadKiosk, and identifyKiosk functions are affected. Any authenticated user can perform actions such as allowing and accepting kiosk registrations, reloading, and identifying kiosks.
Recommendations Update to version 6.5.3 or later.

Exploit

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66397
GHSA-32VR-CH3P-WMR5

Produtos afetados

Churchcrm