PT-2026-30940 · Churchcrm · Churchcrm

·

CVE-2026-35573

·

Published

2026-04-07

·

Updated

2026-04-07

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChurchCRM versions prior to 6.5.3
Description ChurchCRM, an open-source church management system, contains a path traversal flaw in its backup restore functionality. Authenticated administrators can exploit this to upload arbitrary files and potentially achieve remote code execution by overwriting Apache .htaccess configuration files. The vulnerability resides in the RestoreJob.php file within the src/ChurchCRM/Backup/RestoreJob.php path. The $rawUploadedFile['name'] parameter is user-controlled, enabling the upload of files with arbitrary names to the /var/www/html/tmp attach/ChurchCRMBackups/ directory.
Recommendations Update ChurchCRM to version 6.5.3 or later.

Exploit

Fix

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35573
GHSA-R6CR-MVR9-F6WX

Affected Products

Churchcrm