PT-2025-51358 · Churchcrm · Churchcrm

Mateusz-Sa

·

Published

2025-12-16

·

Updated

2025-12-21

·

CVE-2025-67874

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.0
Description The application returns passwords submitted by users in plain text within HTTP responses. This disclosure of credentials could lead to their compromise and potentially amplify the impact of other issues like Cross-Site Scripting (XSS), Improper Access Control (IDOR), and session fixation, allowing attackers to obtain user passwords.
Recommendations Update to version 6.5.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-67874
GHSA-P98H-5XCJ-5C6X

Affected Products

Churchcrm