PT-2025-51926 · Churchcrm · Churchcrm

Guilhermemury

·

Published

2025-12-17

·

Updated

2025-12-20

·

CVE-2025-67877

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, contains a SQL injection issue. The vulnerability resides in the src/CartToFamily.php file, specifically in the handling of the PersonAddress POST parameter. The PersonAddress parameter lacks proper type casting, unlike other parameters in the same file, allowing for the injection of arbitrary SQL commands.
Recommendations Update to version 6.5.3 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-67877
GHSA-H3VQ-9GR6-H9R4

Affected Products

Churchcrm