PT-2025-51922 · Churchcrm · Churchcrm
Lukasz-Rybak
·
Published
2025-12-17
·
Updated
2025-12-20
·
CVE-2025-67876
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions 6.4.0 and prior
Description
ChurchCRM is an open-source church management system affected by a stored cross-site scripting (XSS) issue. A user with the “Manage Groups” permission can inject persistent JavaScript into group role names. This malicious code is stored in the database and executed when any user views pages displaying that role, such as
GroupView.php or PersonView.php. This can lead to full session hijacking and account takeover. The vulnerability impacts the display of group roles, potentially affecting any page that renders this information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Churchcrm