PT-2025-41335 · Churchcrm · Churchcrm

Uartu0

·

Published

2025-10-09

·

Updated

2025-10-09

·

CVE-2025-11529

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 5.18.0
Description A security flaw exists in ChurchCRM impacting the AuthMiddleware function within the src/ChurchCRM/Slim/Middleware/AuthMiddleware.php file of the API Endpoint component. This allows for missing authentication and can be exploited remotely. The exploit has been publicly released.
Recommendations Apply the patch identified as 3a1cffd2aea63d884025949cfbcfd274d06216a4.

Exploit

Fix

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-11529

Affected Products

Churchcrm