PT-2026-30939 · Churchcrm · Churchcrm

Mateusz-Sa

·

Published

2026-04-07

·

Updated

2026-04-07

·

CVE-2026-35572

CVSS v4.0

7.0

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, is susceptible to Server-Side Request Forgery (SSRF). By providing a specially crafted URL within the Referer request header, an attacker can initiate HTTP/HTTPS requests to arbitrary hosts. The server then makes an outbound request to a domain controlled by the attacker, as confirmed by Outbound Asset Scanning Testing (OAST).
Recommendations Update to version 6.5.3 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-35572

Affected Products

Churchcrm