PT-2025-51932 · Churchcrm · Churchcrm

Lukasz-Rybak

·

Published

2025-12-17

·

Updated

2025-12-20

·

CVE-2025-68400

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM is an open-source church management system with a SQL Injection issue present in a legacy endpoint. The vulnerability exists in the /Reports/ConfirmReportEmail.php endpoint and is exploitable through the familyId parameter. Any authenticated user, even with limited permissions, can trigger the SQL injection. The vulnerable code, though removed from the user interface, remains accessible directly via URL, representing a case of 'dead but reachable code'.
Recommendations Update to version 6.5.3 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-68400
GHSA-V54G-2PVG-GVP2

Affected Products

Churchcrm